Skip to content

Latest commit

 

History

History
executable file
·
50 lines (26 loc) · 1.35 KB

entra-id.persistence.backdoor-application.md

File metadata and controls

executable file
·
50 lines (26 loc) · 1.35 KB
title
Backdoor Entra ID application

Backdoor Entra ID application

Platform: Entra ID

MITRE ATT&CK Tactics

  • Persistence
  • Privilege Escalation

Description

Backdoors an existing Entra ID application by creating a new password credential on the app registration.

Warm-up:

  • Create an Entra ID application
  • Assign it the User.Read.All permission at the tenant level (for illustration purposes)

Detonation:

  • Backdoor the Entra ID application by creating a new password credential

References:

Instructions

stratus detonate entra-id.persistence.backdoor-application

Detection

Using Entra ID audit logs with the activity type Update application – Certificates and secrets management.