Terminology Index
Glossary
1801 terms
Showing 161-192 of 1801 terms
A11
Azure Incident Investigation
Investigating a security incident in Microsoft Azure using its logs and signals, such as Entra ID sign-in logs, activity logs, and Microsoft Defender alerts, to determine what an attacker did and how far they reached.
Azure investigations pull from identity, control-plane, and resource logs to reconstruct activity and scope compromise. Because so many Azure attacks begin with identity, sign-in and audit logs are central, and preserving them is a prerequisite for a sound investigation.
Introduced in: Cloud Incident Response
Examples
- Reviewing Entra ID sign-in logs to confirm a compromised account's activity.
- Using Azure activity logs to see what resources an attacker changed.
- Correlating Defender alerts with activity logs to build a timeline.
No related terms linked yet.
B21
