

Tracing Identity Attacks in Azure & Microsoft 365
Instructor
Somil Tyagi, MDR Analyst at Palo Alto Networks Unit42.
Master’s‑educated Cybersecurity professional with Fortune 100 security fusion center experience, specializing in Incident Response, Cloud and Container Security, and automation. Experienced in investigating high‑impact compromises, including APT‑level attacks, with additional expertise in attack emulation, reverse engineering, and digital forensics.
What You'll Learn :
How common identity attack flows in Azure AD/Entra ID leave traces across authentication and workload logs.
How attackers abuse Microsoft 365 services like Teams, Exchange, and SharePoint — and which log sources reveal those actions.
How to quickly map raw telemetry fields back to attacker behaviour.
A preview of the full workshop: moving from isolated alerts to a complete incident storyline.
Who this workshop is for
SOC analysts who see cloud alerts but want to understand the log evidence behind them. Detection engineers who need to connect Azure/M365 telemetry fields to attacker tactics. Threat hunters and responders looking to sharpen their skills in cloud‑focused investigations. Anyone curious about how attackers exploit Microsoft cloud services and how defenders can catch them.
Requirements:
No prior Azure experience needed. The session starts with the services and log sources, then moves into the security side.
If you can read a log and you know what a query is, you're qualified.
Why This Session Exists
Enterprises have already shifted their most valuable data and workflows into the cloud. Yet most vendor training still focuses on product features, not on how to run a full incident response in cloud environments. That leaves defenders with gaps — reports that capture “account compromised” but miss the bigger picture of persistence, privilege escalation, or lateral movement across workloads. This lightning session helps close that gap. You’ll learn how to use Azure and Microsoft 365 logs more effectively, connect traces back to attacker behaviour, and strengthen your investigations so your reports tell the full story of the compromise — not just the aftermath.
What's included
Live, instructor‑led teaser session (30 minutes).
Both attacker and defender perspectives on the same traces. Hands‑on walkthrough of selected Azure/M365 logs, showing how to spot attacker actions in real telemetry.