detecting-azure-service-principal-abuse skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Detect Azure service principal abuse in Microsoft Entra ID using KQL detection Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/detecting-azure-service-principal-abuse/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-azure-service-principal-abuse, or copy the skill folder into ~/.claude/skills/detecting-azure-service-principal-abuse/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-azure-service-principal-abuse/SKILL.md

SKILL.md (verbatim)

name: detecting-azure-service-principal-abuse
description: Detect Azure service principal abuse in Microsoft Entra ID using KQL detection
  queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added
  credentials, privileged role assignment, admin consent bypass, and service principal
  enumeration. Use when investigating suspected privilege escalation or persistence
  via service principals, or building threat-hunting queries for Entra ID identity
  abuse.
domain: cybersecurity
subdomain: cloud-security
tags:
- azure
- entra-id
- service-principal
- privilege-escalation
- credential-abuse
- detection
- splunk
- sentinel
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Token Binding
- Restore Access
- Application Protocol Command Analysis
- Reissue Credential
- Network Isolation
nist_csf:
- PR.IR-01
- ID.AM-08
- GV.SC-06
- DE.CM-01
mitre_attack:
- T1078.004
- T1098.001
- T1528
- T1550.001
- T1098.003

Detecting Azure Service Principal Abuse

Overview

Azure service principals are identity objects used by applications, services, and automation tools to access Azure resources. Attackers exploit service principals for privilege escalation, lateral movement, and persistent access. Key abuse patterns include: adding credentials to existing principals, assigning privileged roles, bypassing admin consent, and enumerating service principals for attack paths. Application ownership grants the ability to manage credentials and configure permissions, creating hidden privilege escalation paths.

When to Use

  • When investigating security incidents that require detecting azure service principal abuse
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Azure subscription with Microsoft Entra ID P2 license
  • Access to Azure AD Audit Logs and Sign-in Logs
  • Microsoft Sentinel or Splunk for SIEM-based detection
  • Microsoft Graph API permissions for investigation
  • Global Reader or Security Reader role minimum

Key Abuse Patterns

1. New Credentials Added to Service Principal

Attackers add new client secrets or certificates to gain persistent access:

Detection Query (KQL - Sentinel):

AuditLogs
| where OperationName has "Add service principal credentials"
    or OperationName has "Update application - Certificates and secrets management"
| extend InitiatedBy = tostring(InitiatedBy.user.userPrincipalName)
| extend TargetSP = tostring(TargetResources[0].displayName)
| extend TargetSPId = tostring(TargetResources[0].id)
| project TimeGenerated, InitiatedBy, OperationName, TargetSP, TargetSPId
| sort by TimeGenerated desc

Detection Query (SPL - Splunk):

index=azure sourcetype="azure:aad:audit"
operationName="Add service principal credentials"
    OR operationName="Update application*Certificates and secrets*"
| stats count by initiatedBy.user.userPrincipalName, targetResources{}.displayName, _time
| sort -_time

2. Privileged Role Assignment to Service Principal

AuditLogs
| where OperationName == "Add member to role"
| extend RoleName = tostring(TargetResources[0].modifiedProperties[1].newValue)
| where RoleName has_any ("Global Administrator", "Application Administrator",
    "Privileged Role Administrator", "Cloud Application Administrator")
| extend TargetSP = tostring(TargetResources[0].displayName)
| extend InitiatedBy = tostring(InitiatedBy.user.userPrincipalName)
| project TimeGenerated, InitiatedBy, TargetSP, RoleName, OperationName

3. Service Principal Enumeration Detection

MicrosoftGraphActivityLogs
| where RequestMethod == "GET"
| where RequestUri has "/servicePrincipals"
| summarize RequestCount = count() by UserAgent, IPAddress, bin(TimeGenerated, 1h)
| where RequestCount > 10
| sort by RequestCount desc
AuditLogs
| where OperationName == "Consent to application"
| extend ConsentType = tostring(TargetResources[0].modifiedProperties[4].newValue)
| where ConsentType has "AllPrincipals"
| extend AppName = tostring(TargetResources[0].displayName)
| extend InitiatedBy = tostring(InitiatedBy.user.userPrincipalName)
| project TimeGenerated, InitiatedBy, AppName, ConsentType

5. OAuth App Permissions Escalation

AuditLogs
| where OperationName == "Add app role assignment to service principal"
| extend AppRoleValue = tostring(TargetResources[0].modifiedProperties[1].newValue)
| where AppRoleValue has_any ("RoleManagement.ReadWrite.Directory",
    "Application.ReadWrite.All", "AppRoleAssignment.ReadWrite.All",
    "Directory.ReadWrite.All", "Mail.ReadWrite")
| extend TargetApp = tostring(TargetResources[0].displayName)
| project TimeGenerated, TargetApp, AppRoleValue, CorrelationId

Investigation Procedures

Step 1: Identify compromised service principal

# List service principals with recently added credentials
Connect-MgGraph -Scopes "Application.Read.All"

$suspiciousSPs = Get-MgServicePrincipal -All | ForEach-Object {
    $sp = $_
    $creds = Get-MgServicePrincipalPasswordCredential -ServicePrincipalId $sp.Id
    $recentCreds = $creds | Where-Object { $_.StartDateTime -gt (Get-Date).AddDays(-7) }
    if ($recentCreds) {
        [PSCustomObject]@{
            DisplayName = $sp.DisplayName
            AppId = $sp.AppId
            ObjectId = $sp.Id
            NewCredsCount = $recentCreds.Count
            LatestCredAdded = ($recentCreds | Sort-Object StartDateTime -Descending | Select-Object -First 1).StartDateTime
        }
    }
}
$suspiciousSPs | Sort-Object LatestCredAdded -Descending

Step 2: Review service principal role assignments

# Check role assignments for a specific service principal
$spId = "<service-principal-object-id>"
Get-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $spId | ForEach-Object {
    $resource = Get-MgServicePrincipal -ServicePrincipalId $_.ResourceId
    [PSCustomObject]@{
        AppRoleId = $_.AppRoleId
        ResourceDisplayName = $resource.DisplayName
        CreatedDateTime = $_.CreatedDateTime
    }
}

Step 3: Check application ownership

# List owners of all applications (ownership = credential control)
Get-MgApplication -All | ForEach-Object {
    $app = $_
    $owners = Get-MgApplicationOwner -ApplicationId $app.Id
    foreach ($owner in $owners) {
        [PSCustomObject]@{
            AppName = $app.DisplayName
            AppId = $app.AppId
            OwnerUPN = $owner.AdditionalProperties.userPrincipalName
            OwnerType = $owner.AdditionalProperties.'@odata.type'
        }
    }
} | Where-Object { $_.OwnerUPN -ne $null }

Step 4: Review sign-in activity

AADServicePrincipalSignInLogs
| where ServicePrincipalId == "<target-sp-id>"
| project TimeGenerated, ServicePrincipalName, IPAddress, Location,
    ResourceDisplayName, Status.errorCode
| sort by TimeGenerated desc

Preventive Controls

Restrict application registration

# Disable user ability to register applications
Update-MgPolicyAuthorizationPolicy -DefaultUserRolePermissions @{
    AllowedToCreateApps = $false
}
# Require admin approval for all app consent requests
New-MgPolicyPermissionGrantPolicy -Id "admin-only-consent" `
    -DisplayName "Admin Only Consent" `
    -Description "Only admins can consent to applications"

Monitor with Microsoft Sentinel Analytics Rules

Create analytics rules for:

  • New service principal credential additions
  • Privileged role assignments to service principals
  • Bulk service principal enumeration
  • Admin consent grants to unknown applications
  • Service principal sign-ins from unusual locations

MITRE ATT&CK Mapping

Technique ID Description
Account Manipulation: Additional Cloud Credentials T1098.001 Adding credentials to service principal
Valid Accounts: Cloud Accounts T1078.004 Using compromised service principal
Account Discovery: Cloud Account T1087.004 Enumerating service principals
Steal Application Access Token T1528 OAuth token theft via service principal

References

  • Splunk Detection: Azure AD Service Principal Abuse
  • Semperis: Service Principal Ownership Abuse in Entra ID
  • MITRE ATT&CK Cloud Matrix
  • Microsoft: Securing service principals in Entra ID

Other files in this skill

assets/template.md (verbatim)

Azure Service Principal Abuse Detection Template

Investigation Checklist

Check Status Notes
Recent credential additions (7 days) [ ]
Privileged role assignments to SPs [ ]
Application ownership review [ ]
Sign-in anomalies for SPs [ ]
Admin consent grants review [ ]
OAuth permission escalation [ ]

Affected Service Principals

Display Name App ID Object ID Finding Type Severity

Remediation Actions

Action Status Completed By Date
Rotate compromised credentials [ ]
Remove unauthorized role assignments [ ]
Disable compromised service principal [ ]
Review and restrict app ownership [ ]
Enable Conditional Access for workload identities [ ]

references/api-reference.md (verbatim)

Azure Service Principal Abuse Detection — API Reference

Libraries

Library Install Purpose
azure-identity pip install azure-identity Azure AD authentication
requests pip install requests Microsoft Graph API client

Microsoft Graph API Endpoints

Method Endpoint Description
GET /v1.0/servicePrincipals List service principals
GET /v1.0/servicePrincipals/{id} Get SP details and credentials
GET /v1.0/servicePrincipals/{id}/appRoleAssignments SP role assignments
GET /v1.0/directoryRoles List directory roles
GET /v1.0/directoryRoles/{id}/members Role members (includes SPs)
GET /v1.0/auditLogs/signIns Sign-in logs for SP activity
GET /v1.0/auditLogs/directoryAudits Directory change audit logs

OAuth2 Token Endpoint

POST https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token
grant_type=client_credentials
scope=https://graph.microsoft.com/.default

High-Privilege Directory Roles

Role Risk
Global Administrator Full tenant control
Application Administrator Can create/manage all apps
Cloud Application Administrator Manage cloud app registrations
Privileged Role Administrator Manage role assignments

Service Principal Abuse Indicators

Indicator Description Severity
Multiple password credentials Possible backdoor persistence HIGH
Expired credentials not removed Credential hygiene gap MEDIUM
SP with Global Admin role Overprivileged automation CRITICAL
Unusual sign-in location Compromised SP credentials HIGH
New credential added to SP Persistence via credential injection CRITICAL

MITRE ATT&CK Mapping

Technique ID Description
Account Manipulation T1098 Add credentials to SP
Valid Accounts: Cloud T1078.004 Abuse SP credentials
Trusted Relationship T1199 Abuse multi-tenant SP trust

External References

references/standards.md (verbatim)

Standards - Detecting Azure Service Principal Abuse

MITRE ATT&CK Techniques

  • T1098.001: Account Manipulation - Additional Cloud Credentials
  • T1078.004: Valid Accounts - Cloud Accounts
  • T1087.004: Account Discovery - Cloud Account
  • T1528: Steal Application Access Token
  • T1550.001: Use Alternate Authentication Material - Application Access Token

CIS Microsoft Azure Foundations Benchmark v2.1

  • 1.11: Ensure that multi-factor authentication is enabled for all privileged users
  • 1.14: Ensure that guest users are reviewed on a regular basis
  • 1.15: Ensure that User consent for applications is set to Do not allow user consent

Microsoft Secure Score Recommendations

  • Require admin approval for unmanaged applications
  • Remove unused application permissions
  • Limit service principal credential lifetime
  • Implement Conditional Access for workload identities

references/workflows.md (verbatim)

Workflows - Detecting Azure Service Principal Abuse

Detection Workflow

1. Log Collection → Ingest Azure AD Audit + Sign-in logs to SIEM
2. Rule Activation → Enable detection analytics for SP abuse patterns
3. Alert Triage → Validate alerts against known automation accounts
4. Investigation → Correlate credential changes with sign-in anomalies
5. Containment → Disable compromised SP, rotate credentials
6. Remediation → Remove unauthorized permissions, review ownership

Investigation Workflow

1. Identify affected service principal (name, object ID, app ID)
2. Review recent credential changes (new secrets/certificates)
3. Check role assignments for privilege escalation
4. Analyze sign-in logs for unusual IPs/locations
5. Review application ownership chain
6. Assess blast radius of compromised permissions
7. Document findings and initiate incident response

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.