← Back to feed
research Elastic Security Labs

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Elastic Security Labs • • Microsoft

Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.

T1592
Read the full story Elastic Security Labs →

Related Coverage

research Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap Elastic Security Labs · Jun 19