Huntbase Hub · All hunts

Threat hunts for Azure

29 hunts covering Azure, each with a hypothesis, the queries that test it and what the hunt cannot see.

29 hunts

  1. high Part 2 of 2
    Research by Microsoft

    Storm-3068 Build Pipeline Execution and Tunneling

    An adversary has modified build pipelines to execute malicious code on agents, deploying RMM tools and establishing tunnels to exfiltrate Kubernetes credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  2. high Part 1 of 2
    Research by Microsoft

    Cloud Identity Takeover and DevOps Enumeration

    An adversary hijacked a cloud identity using self-service password reset to perform automated discovery across Azure DevOps repositories and harvest Kubernetes configuration files.

    4 query2 analytic2 checkpoint1 action3 task
    command and control · credential access · discovery
  3. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Exfiltration and Impact

    An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  4. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Persistence and AD Credential Harvesting

    An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  5. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee Delivery and C2 Establishment

    An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  6. high
    Research by Cisco Talos

    Microsoft Patch Tuesday September 2026 Exposure

    An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-58599 · CVE-2026-65669
  7. high Part 2 of 2
    Research by Microsoft

    Storm-3168 Web Application Probing

    An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  8. high Part 1 of 2
    Research by Microsoft

    Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition

    A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  9. high Part 1 of 2
    Research by The DFIR Report

    Bumblebee Delivery and Persistence

    An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · exfiltration
  10. high Part 1 of 2
    Research by Huntress

    Sideloaded AppX OAuth Token Theft

    An adversary has enabled Developer Mode and sideloaded a malicious AppX package to abuse WWAHost.exe, allowing them to capture MFA-compliant OAuth tokens via a legitimate Microsoft login dialog.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  11. high Part 2 of 2
    Research by The DFIR Report

    Bissa Scanner C2 and S3 Exfiltration

    An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  12. high Part 1 of 2
    Research by The DFIR Report

    Bissa Scanner Mass Exploitation and Credential Harvesting

    An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-9501
  13. high
    Research by Elastic Security Labs

    Rapid Phishing and Proxy-based Exfiltration

    An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  14. medium
    Research by Elastic Security Labs

    Rapid Identity Breakout and Exfiltration

    An adversary uses a compromised privileged identity to exfiltrate data via a multi-hop proxy or tunnel within 30 minutes of initial access, moving faster than traditional telemetry export batches.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  15. medium Part 2 of 2
    Research by Microsoft

    Cloud Workload Identity and Network Triage

    An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  16. medium Part 1 of 2
    Research by Microsoft

    Cloud Workload Runtime and Exploitation Behavior

    An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.

    3 query2 analytic2 checkpoint1 action3 task
    command and control · credential access · defense evasion
  17. high
    Research by Huntress

    AD RMS Discovery and Administrative Reconnaissance

    An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · privilege escalation
  18. high
    Research by Red Canary

    Entra ID Agent User Impersonation and Teams Abuse

    An attacker uses the Entra ID Agent User OAuth flow to impersonate an AI agent and dispatch malicious content via Microsoft Teams using Graph API cmdlets.

    3 query1 analytic1 checkpoint1 action2 task
    execution · initial access
  19. high
    Research by Elastic Security Labs

    Bulk Directory Discovery via AAD Graph API

    An adversary uses legacy Azure AD Graph API endpoints and known offensive Client IDs to perform bulk directory enumeration, specifically targeting internal API versions that expose sensitive authentication methods.

    3 query2 analytic2 checkpoint1 action2 task
    discovery · execution · initial access
  20. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  21. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  22. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  23. medium
    Research by Elastic Security Labs

    Suspicious ingress tool transfer via native utilities

    An adversary is using native Linux or macOS utilities like curl or wget to download malicious payloads from external infrastructure, hiding their activity within the high volume of legitimate cloud automation.

    3 query1 analytic1 checkpoint1 action2 task
    command and control
  24. high Part 2 of 2
    Research by Microsoft

    AI Infrastructure Host Monetization and Persistence

    An attacker has compromised an AI gateway or retrieval engine and is now deploying masqueraded payloads to monetize the host via cryptomining and establish durable SSH or systemd persistence.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  25. high Part 1 of 2
    Research by Microsoft

    AI Gateway Exploitation and Data Theft

    An intruder has exploited an exposed AI gateway or orchestration platform to harvest LLM API keys from process memory and exfiltrate tenant configurations from backend databases.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  26. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  27. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  28. high Part 2 of 2
    Research by Microsoft

    Microsoft Graph and Cloud Application Exfiltration

    An adversary is using automated Graph API tools to enumerate organizational resources and exfiltrate SharePoint/OneDrive data after obtaining a cloud session via passkey-themed social engineering.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · exfiltration · initial access
  29. high Part 1 of 2
    Research by Wiz

    TeamPCP Credential Validation and Discovery

    An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · exfiltration