Most cloud incidents are not a breach of the provider's Hypervisor, but rather exploitation of a customer error: overly broad permissions, open Storage, or a user without MFA. The attacker doesn't 'breach' — they connect.
Key Attack Vectors
- Public Storage Buckets — Container opened for Anonymous Read and leaked to the internet.
- Password Spraying — One common password against thousands of accounts, so as not to lock them out.
- Token Theft / Pass-the-Cookie — Stealing a Refresh Token from the browser completely bypasses MFA.
- Illicit Consent Grant — A malicious application requests OAuth permissions, and the user approves it themselves.
- Golden SAML — Breaching ADFS and creating signed Tokens for any user.
- Over-Privileged Managed Identity — A VM with Contributor permissions allowing lateral movement.
Attacks on the left, log evidence on the right. A public storage container shows anonymous reads in storage access logs. Password spraying shows many 50126 failures from one IP in sign-in logs. Token theft or pass-the-cookie shows a sign-in from a new IP where MFA is 'satisfied by claim'. An illicit consent grant shows a 'Consent to application' entry in the audit log. Golden SAML shows a cloud sign-in with no matching on-prem ADFS event. An over-privileged managed identity shows a role assignment made by a VM identity in the activity log. The takeaway: the attacker does not break in, the attacker signs in.
What to check in Logs
- Entra Sign-in Logs — Successful logins from an unusual country, Impossible Travel, multiple failures then success.
- Audit Logs — Adding Credentials to an application, changing Global Admins group, adding Federation .
- Activity Log — Unusual resource creation (Crypto Mining), NSG rule changes.
- Storage Diagnostic Logs — Anonymous access and downloads of unusual volume.