← Back to feed
research Elastic Security Labs

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Elastic Security Labs Microsoft

Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.

T1592
Read the full story Elastic Security Labs →

Related Coverage

research Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap Elastic Security Labs · Jun 19