Blue Team | Hunting Cloud Persistence Without Malware

Blue Team | Hunting Cloud Persistence Without Malware

🎙 Ankit Gupta and Shilpi Mittal 👥 70K 📅 February 17, 2026 ⏱ 19 min 👁 156 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

cloud-native persistenceOAuth abusetoken replayKQL huntingMITRE ATT&CK

Summary

The presentation by Ankit Gupta and Shilpi Mittal at SANS Hack & Defend Summit 2025 focuses on detecting cloud-native persistence techniques that operate without malware, often evading traditional security tools. The speakers define ‘silent compromise’ as intrusions that slip past defenses using legitimate cloud features. They outline attack vectors including illicit consent OAuth apps, service principal abuse, token replay, and API key misuse. The talk emphasizes hunting strategies across identity, apps, mail, and data layers, using telemetry correlation and UEBA. Practical KQL queries are provided for detecting high-risk OAuth consents and abnormal refresh token usage. Case studies from Unit 42, CVE-2025-3928, and Microsoft AI data exposure illustrate real-world incidents. The action plan includes enabling audit logs, requiring admin approval for app consents, deploying hunt queries, automating response playbooks, and conducting weekly reviews of app registrations. The session concludes with a call to integrate these practices into regular security operations.

149 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable, actionable insights for blue teams, emphasizing real-world attack techniques and practical hunting methods. The speakers argue convincingly that modern attackers leverage legitimate cloud features, making detection challenging. They support their points with case studies and concrete examples, though the argumentation is more experience-based than rigorously data-driven. The value lies in the practical KQL queries and the layered hunting framework, which can be directly applied by SOC analysts.

80 words

Title / Content Match

The title accurately reflects the content, focusing on hunting cloud persistence without malware.

Quality & Reliability

7/10

The talk provides practical, experience-based insights from senior security engineers, with references to real-world cases and MITRE ATT&CK. However, it lacks detailed technical depth and formal citations, and the presentation is high-level.

Key Moments

Cited Sources

  • MITRE ATT&CK for Cloud — Referenced as a framework for mapping persistence techniques.
  • Unit 42 — Mentioned in case study about AWS credential theft.
  • CVE-2025-3928 — Referenced as a zero-day in Azure exploited for persistence.

Concurring Sources

Contribution & Novelties

The talk provides a practical, layered approach to hunting cloud-native persistence, emphasizing the use of KQL queries and behavioral analytics. It offers ready-to-deploy detection queries and a framework for mapping persistence across identity, API, and data layers. The case studies illustrate real-world scenarios, making the content actionable for blue teams.

Pour aller plus loin :

101 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, indicating a well-rounded presentation. The technical level is slightly lower, suggesting the content is accessible to a broad audience, while reliability is solid due to practical experience.

Reliability 7/10

💬 No comments were provided for analysis.