Seeing Through the Fog: Interpreting Entra ID Signals During AiTM Attacks @FIRSTdotorg
Seeing Through the Fog: Interpreting Entra ID Signals During AiTM Attacks  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 1 hour ago
Pierre Audonnet (Microsoft, CA)

This session focuses on what AiTM activity looks like inside Entra ID: the key authentication events, token behaviors, and anomalies attackers leave behind. We then cover how to surface and interpret these signals, using KQL only as an example to navigate telemetry (especially since Entra ID logs are often unclear or incomplete).

Attendees leave with a clear takeaway: practical patterns, investigative cues, and a short list of effective mitigations to quickly detect and block AiTM techniques in real environments.

---

For the past decade, Pierre Audonne has worked with SOC teams of all sizes to help them detect, investigate, and respond to modern threats. Pierre's primary focus is the Microsoft identity stack (Entra ID and the full suite of on-premises Active Directory technologies). He specializes in understanding attacker tradecraft and translating it into practical detection strategies for defenders. When he's not helping my customers with their cyber fires, he's creating and teaching technical workshops and helping large organizations deploy Zero Trust architecture.
Seeing Through the Fog: Interpreting Entra ID Signals During AiTM AttacksBreaking the SIEM ConfinementHunting Cyber Threat Intelligence on TelegramCyber Deception 2.0: Adaptive Honeynets and Canary Intelligence in ProductionWhats New in CSAF v2.1: Key Updates ExplainedArcana: A Unified Framework for Incident Response Documentation and Knowledge ManagementFrom Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE RemediationLightning Talks!Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant)What Can Cybersecurity Incident Responders Learn from Real-World Crises?Enhancing Incident Response with AWS CIRT, MSSPs, and ISVsEpisode 55: Merike Kaeo, FIRSTCON26 Program Chair
FIRST |

Seeing Through the Fog: Interpreting Entra ID Signals During AiTM Attacks

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER