Talk With an Expert

Snakes on a (Control) Plane: Purple-Teaming Azure IAM for Threat Detection

Snakes on a (Control) Plane: Purple-Teaming Azure IAM for Threat Detection (PDF, 1.94MB)Last updated: 02 Oct, 2025
Presented by:
Lydia Graslie
Lydia Graslie

Cloud-based identity security is notoriously slippery: every cloud has a different security philosophy and the actions that cloud logs describe are not always easy for a defender to visualize.

This is especially true for Azure, with its complex web of roles, groups, subscriptions, and similar-sounding settings. Luckily, with a little grit, purple-teaming, and the scientific method, we can wrangle actionable understanding out of whatever cloud dens we may find ourselves in.

This presentation provides a repeatable framework for purple-teaming cloud threat detection and explains key descriptors that should be captured as part of Azure threat research.

Learning Objectives:

- Overview of cloud purple teaming as applied to Azure

- Research framework for cloud purple teaming

- Key descriptors to include in threat detection research

SANS CloudSecNext Summit 2025