<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>T1098.001 on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/t1098.001/</link><description>Recent content in T1098.001 on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Fri, 29 May 2026 10:56:48 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/t1098.001/index.xml" rel="self" type="application/rss+xml"/><item><title>Entra ID Post-Credential Activity Detection: Service Principal Staging and Privileged Role Escalation</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</link><pubDate>Fri, 29 May 2026 10:56:48 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</guid><description>Three new hunting queries target Midnight Blizzard-style persistence patterns — service principal credential staging, privileged role assignments to new accounts, and Temporary Access Pass abuse.</description></item><item><title>Entra ID Identity Boundary Expansion: Three New Hunting Queries for Stealthy Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</link><pubDate>Thu, 28 May 2026 11:14:14 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</guid><description>Added three hunting queries targeting identity boundary expansion techniques in Entra ID that escalate privileges without creating new accounts.</description></item><item><title>Entra ID Authentication Anomalies: Advanced Hunting for Privilege Abuse and Defense Evasion</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</link><pubDate>Wed, 27 May 2026 13:42:33 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</guid><description>Adds three-query pack detecting legacy auth bypass, guest account abuse, and post-reset privileged operations.</description></item><item><title>Entra ID Attack Chain Correlation: Three New Hunting Queries for Sequential Compromise Patterns</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14311/</link><pubDate>Tue, 26 May 2026 08:14:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14311/</guid><description>Three hunting queries detect multi-event attack chains in Entra ID—privileged role grants followed by SP credential additions and MFA disabling followed by sign-ins from unknown IPs.</description></item><item><title>AWS Content Quality Overhaul: Standardized Detection Rules and Improved Entity Mappings</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</link><pubDate>Mon, 18 May 2026 07:30:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</guid><description>Comprehensive quality improvements to 61 AWS Analytic Rules and 35 Hunting Queries with standardized naming conventions, normalized MITRE technique mappings, and updated entity field references from legacy AccountCustomEntity to UserIdentityUserName.</description></item><item><title>Microsoft Entra ID: Service Principal Credential Manipulation by Rare Actors</title><link>http://sentinelchangelog.net/posts/2026-05-07-pr-14213/</link><pubDate>Thu, 07 May 2026 10:51:04 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-07-pr-14213/</guid><description>Identifies service principal credential additions by actors not observed performing these operations in the previous 90 days, targeting persistence techniques.</description></item></channel></rss>