Skip to main content
AD Academy
Cloud Computing: Architecture and Security
Beginner14 minLast updated: Topic 8 of 8

Common Cloud Attacks and What to Identify in Logs

Misconfiguration, Token theft, Consent Phishing, and monitoring.

Not read

What you will learn here

  • Key Attack Vectors
  • What to check in Logs
  • Misconfiguration, Token theft, Consent Phishing, and monitoring.

Worth reading first:Storage, Backup, and Disaster Recovery (BCDR)

Most cloud incidents are not a breach of the provider's Hypervisor, but rather exploitation of a customer error: overly broad permissions, open Storage, or a user without MFA. The attacker doesn't 'breach' — they connect.

Key Attack Vectors

  • Public Storage Buckets — Container opened for Anonymous Read and leaked to the internet.
  • Password Spraying — One common password against thousands of accounts, so as not to lock them out.
  • Token Theft / Pass-the-Cookie — Stealing a Refresh Token from the browser completely bypasses MFA.
  • Illicit Consent Grant — A malicious application requests OAuth permissions, and the user approves it themselves.
  • Golden SAML — Breaching ADFS and creating signed Tokens for any user.
  • Over-Privileged Managed Identity — A VM with Contributor permissions allowing lateral movement.

Attacks on the left, log evidence on the right. A public storage container shows anonymous reads in storage access logs. Password spraying shows many 50126 failures from one IP in sign-in logs. Token theft or pass-the-cookie shows a sign-in from a new IP where MFA is 'satisfied by claim'. An illicit consent grant shows a 'Consent to application' entry in the audit log. Golden SAML shows a cloud sign-in with no matching on-prem ADFS event. An over-privileged managed identity shows a role assignment made by a VM identity in the activity log. The takeaway: the attacker does not break in, the attacker signs in.

Short and clear

  • Most cloud incidents are misconfiguration, not a breach of the provider.
  • Token theft and pass-the-cookie bypass MFA — the tell is MFA 'satisfied by claim' from a new IP.
  • Consent phishing abuses the user directly: they approve OAuth permissions for a malicious app.
  • Sign-in logs, audit logs and the activity log are the first three places to check.

Real-life exampleAn employee approved an MFA push by mistake; sign-in logs showed a successful foreign login and the audit log showed a new mailbox forwarding rule sending mail to the attacker.

What to check in Logs

  • Entra Sign-in Logs — Successful logins from an unusual country, Impossible Travel, multiple failures then success.
  • Audit Logs — Adding Credentials to an application, changing Global Admins group, adding Federation .
  • Activity Log — Unusual resource creation (Crypto Mining), NSG rule changes.
  • Storage Diagnostic Logs — Anonymous access and downloads of unusual volume.

Check yourself

Which attack bypasses MFA without knowing the password?

What is Illicit Consent Grant?

Was this page helpful?