azure analytic rules for APT29

Job ID: 34766891

Budget: £20 – £250 GBP

Hi This is to mitigate against APT29 potential artefacts and create analytics to detect them

Can you create Azue analytic rules for the following

1 SAML detect if ADFS is in use and highlight potential vulnerabilities
2 Azure AAD Federated Domains detect any new domains added
3 Azure AAD Federated Domains detect new token signing certificate on existing domain
4 Azure AAD Detect if cloud only account has an immutableD
5 Apps. Detect when new secret added. For Example read all mail
6 Cross tenant: Detect if we have cross tenant access. Look for sign ins
7 MFA Check enrolment can occur from conditional access locations
8 MFA Check token added to dormant account Ads
Related categories: Data Analytics Microsoft Azure