ConsentStorm

ConsentStorm is a blue team lab that falls under the Cloud Forensics category and will cover the following subjects: Microsoft Sentinel, Entra ID Sign-in Logs, Entra ID Audit Logs, Azure Activity Logs, Office 365 Audit Logs, Azure Diagnostics Logs, KQL Query Editor, Initial Access, Persistence, Privilege Escalation, Stealth, Defense Impairment, Credential Access, Discovery, Lateral Movement, Collection, Exfiltration.

Learning Objectives

Investigate a cloud OAuth intrusion by identifying malicious consent grants (Q1-Q4), tracing service-account pivots and Azure enumeration (Q5-Q11), validating persistence through app secrets, TAP abuse, and group changes (Q12-Q17), analyzing file access and exfiltration (Q18-Q19), and mapping tradecraft to ATT&CK and Entra mitigations (Q20-Q25).

Categories: Cloud Forensics.

MITRE ATT&CK Tactics: Initial Access, Persistence, Privilege Escalation, Stealth, Defense Impairment, Credential Access, Discovery, Lateral Movement, Collection, Exfiltration.

Tools: Microsoft Sentinel, Entra ID Sign-in Logs, Entra ID Audit Logs, Azure Activity Logs, Office 365 Audit Logs, Azure Diagnostics Logs, KQL Query Editor.

Difficulty: medium.