azure analytic rules for APT29
Budget: £20 – £250 GBP
Hi This is to mitigate against APT29 potential artefacts and create analytics to detect them
Can you create Azue analytic rules for the following
1 SAML detect if ADFS is in use and highlight potential vulnerabilities
2 Azure AAD Federated Domains detect any new domains added
3 Azure AAD Federated Domains detect new token signing certificate on existing domain
4 Azure AAD Detect if cloud only account has an immutableD
5 Apps. Detect when new secret added. For Example read all mail
6 Cross tenant: Detect if we have cross tenant access. Look for sign ins
7 MFA Check enrolment can occur from conditional access locations
8 MFA Check token added to dormant account Ads
Can you create Azue analytic rules for the following
1 SAML detect if ADFS is in use and highlight potential vulnerabilities
2 Azure AAD Federated Domains detect any new domains added
3 Azure AAD Federated Domains detect new token signing certificate on existing domain
4 Azure AAD Detect if cloud only account has an immutableD
5 Apps. Detect when new secret added. For Example read all mail
6 Cross tenant: Detect if we have cross tenant access. Look for sign ins
7 MFA Check enrolment can occur from conditional access locations
8 MFA Check token added to dormant account Ads