← Back to feed
research Elastic Security Labs

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Elastic Security Labs Microsoft

Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.

T1592
Read the full story Elastic Security Labs →

Related Coverage

research 24th August – Threat Intelligence Report Check Point Research · Aug 24 research How a team of entity maintainers monitors, connects and scores entities in Elastic Security Elastic Security Labs · Aug 24 research Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 · Aug 21