<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Azure Forensics — Blog</title>
    <link>https://www.azureforensics.app/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:41:46 GMT</lastBuildDate>
    <atom:link href="https://www.azureforensics.app/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Azure log forensics limits: retention and missing logs</title>
      <link>https://www.azureforensics.app/en/blog/azure-log-forensics-limitations</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/azure-log-forensics-limitations</guid>
      <description>Azure Activity Log retention is 90 days and resource logs are off by default. What each Azure log cannot tell you, and how to write an honest conclusion.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>An Azure breach, walked through (fictional case)</title>
      <link>https://www.azureforensics.app/en/blog/azure-breach-walkthrough-fictional</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/azure-breach-walkthrough-fictional</guid>
      <description>A fictional Azure breach investigated end to end: leaked app secret, self-assigned role, Run Command, stolen managed identity token, Key Vault and blob theft.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Managed identity and service principal abuse in Azure</title>
      <link>https://www.azureforensics.app/en/blog/azure-managed-identity-app-registration-abuse</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/azure-managed-identity-app-registration-abuse</guid>
      <description>How attackers abuse Azure service principals and managed identities: leaked secrets, IMDS token theft, federated credentials, runbooks, and the log signals.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>NSG and VNet flow logs analysis for exfiltration</title>
      <link>https://www.azureforensics.app/en/blog/nsg-vnet-flow-logs-exfiltration</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/nsg-vnet-flow-logs-exfiltration</guid>
      <description>NSG and VNet flow logs analysis for incident response: tuple formats, bytes and flow states, spotting exfiltration, mining and attacker IPs, blind spots.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Azure defense evasion: deleted logs and disabled Defender</title>
      <link>https://www.azureforensics.app/en/blog/azure-defense-evasion-diagnostic-settings</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/azure-defense-evasion-diagnostic-settings</guid>
      <description>Deleted diagnostic settings, removed Activity Log export, Defender plans set to Free, locks and NSG rules: spotting Azure defense evasion, and what survives.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Azure Storage data exfiltration: SAS tokens and blob logs</title>
      <link>https://www.azureforensics.app/en/blog/azure-storage-sas-data-exfiltration</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/azure-storage-sas-data-exfiltration</guid>
      <description>Investigate Azure Storage data exfiltration: listAccountSas and listKeys in the Activity Log, GetBlob bursts in blob logs, SAS token hashes, what to rotate.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Key Vault audit logs: who read which secret, and when</title>
      <link>https://www.azureforensics.app/en/blog/key-vault-audit-logs-secret-access</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/key-vault-audit-logs-secret-access</guid>
      <description>Use Azure Key Vault audit logs (AuditEvent) to find who read which secret: SecretGet and SecretList, access policy changes, new principals and enumeration.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Azure Run Command attacks: investigating VM execution</title>
      <link>https://www.azureforensics.app/en/blog/azure-run-command-attack</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/azure-run-command-attack</guid>
      <description>How attackers use Azure VM Run Command and the Custom Script Extension, what the Activity Log records (and omits), and which on-VM artifacts hold the script.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Azure role assignment abuse and elevateAccess, investigated</title>
      <link>https://www.azureforensics.app/en/blog/azure-role-assignment-abuse-elevate-access</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/azure-role-assignment-abuse-elevate-access</guid>
      <description>How attackers escalate with Azure role assignments and elevateAccess, what roleAssignments/write events look like in the Activity Log, and how to triage them.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Azure Activity Log analysis, step by step, in your browser</title>
      <link>https://www.azureforensics.app/en/blog/analyze-azure-logs-with-azure-forensics</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/analyze-azure-logs-with-azure-forensics</guid>
      <description>Step-by-step Azure Activity Log analysis with the free Azure Forensics analyzer: load exports, read the verdict, findings, timeline and entities, export.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to export the Azure Activity Log and resource logs</title>
      <link>https://www.azureforensics.app/en/blog/export-azure-activity-log-resource-logs</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/export-azure-activity-log-resource-logs</guid>
      <description>Export the Azure Activity Log, Key Vault, storage and flow logs for an investigation: portal, az CLI, Log Analytics and storage exports, and the traps.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Azure subscription compromised? An incident response guide</title>
      <link>https://www.azureforensics.app/en/blog/azure-incident-response-compromised-subscription</link>
      <guid isPermaLink="true">https://www.azureforensics.app/en/blog/azure-incident-response-compromised-subscription</guid>
      <description>Think your Azure subscription is compromised? Which logs to preserve first, the operations that betray an attacker, and how to go from Activity Log to verdict.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>