Blog

Recent
Cloud Detection & Response

Have I Been Pwned? Detecting Entra ID Persistence Before Your SIEM Even Existed

Most detection content catches persistence techniques as they happen. But what if the attacker was already there before you connected your logs? CloudTwin™ analyzes Entra ID configuration state — not just log events — to answer the question every SOC team should be asking: "Have I been pwned?"
Petr Zuzanov
Petr Zuzanov
May 14
12
min
All posts
Petr Zuzanov
Petr Zuzanov
Aug 26, 2025
7
min
Stream Team
Stream Team
Aug 21, 2025
min

What's new