Detection rules › YARA-L
Entra ID Login Activity to Azure AD PowerShell Application
Logins to Azure AD PowerShell app can have legitimate purposes, but are also abused to gain access to user information. Programatic access to Azure AD should generally be through other apps
Telemetry coverage
Rule body
// Copyright 2025 Google LLC. Licensed under Apache-2.0.
rule entra_id_login_activity_to_azure_ad_powershell_app {
meta:
author = "Google Cloud Security"
description = "Logins to Azure AD PowerShell app can have legitimate purposes, but are also abused to gain access to user information. Programatic access to Azure AD should generally be through other apps"
rule_id = "mr_5bce885a-7f65-41e1-ae94-9befc892d704"
rule_name = "Entra ID Login Activity to Azure AD PowerShell Application"
type = "hunt"
platform = "azure"
data_source = "azure ad"
severity = "Medium"
priority = "Medium"
events:
$login.metadata.event_type = "USER_LOGIN"
$login.metadata.product_name = "Azure AD"
$login.metadata.vendor_name = "Microsoft"
$login.target.application = "Azure Active Directory PowerShell"
$login.security_result.action = "ALLOW"
$login.target.user.userid = $userid
match:
$userid over 5m
outcome:
$risk_score = 65
$event_count = count_distinct($login.metadata.id)
$target_application = array_distinct($login.target.application)
$security_description = array_distinct($login.security_result.description)
$security_summary = array_distinct($login.security_result.summary)
$country_region_login_attempt = array_distinct(strings.concat($login.principal.location.city," ",$login.principal.location.state," ",$login.principal.location.country_or_region))
$user_agent = array_distinct($login.network.http.user_agent)
$principal_ip = array_distinct($login.principal.ip)
condition:
$login
}
YARA-L rule structure
Condition
Fires when at least one $login event in the 5m window.
Events
$login
target.application = "Azure Active Directory PowerShell"security_result.action = "ALLOW"
Match and correlation
Outcome
Outcome variables add context to a detection. When the rule generates an alert, $risk_score is displayed with it.
| Field | Expression |
|---|---|
risk_score | 65 |
event_count | count_distinct($login.metadata.id) |
target_application | array_distinct($login.target.application) |
security_description | array_distinct($login.security_result.description) |
security_summary | array_distinct($login.security_result.summary) |
country_region_login_attempt | array_distinct(strings.concat($login.principal.location.city," ",$login.principal.location.state," ",$login.principal.location.country_or_region)) |
user_agent | array_distinct($login.network.http.user_agent) |
principal_ip | array_distinct($login.principal.ip) |