
Blue Team | Hunting Cloud Persistence Without Malware
Keywords
Summary
149 words
Critical Evaluation
Value of the Information & Strength of the Argument
The talk provides valuable, actionable insights for blue teams, emphasizing real-world attack techniques and practical hunting methods. The speakers argue convincingly that modern attackers leverage legitimate cloud features, making detection challenging. They support their points with case studies and concrete examples, though the argumentation is more experience-based than rigorously data-driven. The value lies in the practical KQL queries and the layered hunting framework, which can be directly applied by SOC analysts.
80 words
Title / Content Match
The title accurately reflects the content, focusing on hunting cloud persistence without malware.
Quality & Reliability
7/10
The talk provides practical, experience-based insights from senior security engineers, with references to real-world cases and MITRE ATT&CK. However, it lacks detailed technical depth and formal citations, and the presentation is high-level.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction and definition of silent compromise
- Attack vectors: OAuth, service principals, token replay, API keys
- Hunting framework: identity, apps, mail, data layers
- Practical KQL queries for OAuth consent and token replay
- Case studies: Unit 42, CVE-2025-3928, Microsoft AI exposure
- Action plan: audit logs, app consent controls, automation, weekly hunts
Cited Sources
- MITRE ATT&CK for Cloud — Referenced as a framework for mapping persistence techniques.
- Unit 42 — Mentioned in case study about AWS credential theft.
- CVE-2025-3928 — Referenced as a zero-day in Azure exploited for persistence.
Concurring Sources
- MITRE ATT&CK for Cloud — Aligns with the talk's emphasis on cloud-specific attack techniques.
Contribution & Novelties
The talk provides a practical, layered approach to hunting cloud-native persistence, emphasizing the use of KQL queries and behavioral analytics. It offers ready-to-deploy detection queries and a framework for mapping persistence across identity, API, and data layers. The case studies illustrate real-world scenarios, making the content actionable for blue teams.
Pour aller plus loin :
- MITRE ATT&CK for Cloud — Essential framework for understanding cloud-specific TTPs.
- Microsoft Sentinel documentation — Official resource for KQL queries and threat hunting.
- OAuth 2.0 specification — Foundational understanding of OAuth flows and security considerations.
- Cloud Security Alliance — Industry guidance on cloud security best practices.
101 words
Radar Profile
The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, indicating a well-rounded presentation. The technical level is slightly lower, suggesting the content is accessible to a broad audience, while reliability is solid due to practical experience.
💬 No comments were provided for analysis.