Terminology Index

Glossary

1801 terms

Open concept maps

Showing 161-192 of 1801 terms

A
11

Azure Incident Investigation

Investigating a security incident in Microsoft Azure using its logs and signals, such as Entra ID sign-in logs, activity logs, and Microsoft Defender alerts, to determine what an attacker did and how far they reached.

Azure investigations pull from identity, control-plane, and resource logs to reconstruct activity and scope compromise. Because so many Azure attacks begin with identity, sign-in and audit logs are central, and preserving them is a prerequisite for a sound investigation.

Introduced in: Cloud Incident Response

Examples

  • Reviewing Entra ID sign-in logs to confirm a compromised account's activity.
  • Using Azure activity logs to see what resources an attacker changed.
  • Correlating Defender alerts with activity logs to build a timeline.

No related terms linked yet.

B
21