CISA Releases Free Detection Tool for Azure/M365 Environment
CISA has created a free tool for detecting unusual and potentially malicious activity that threatens users and applications in an Azure/Microsoft O365 environment. The tool is intended for use by incident responders and is narrowly focused on activity that is endemic to the recent identity- and authentication-based attacks seen in multiple sectors.
Sparrow.ps1 was created by CISA’s Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment. The tool is intended for use by incident responders, and focuses on the narrow scope of user and application activity endemic to identity and authentication based attacks seen recently in multiple sectors. It is neither comprehensive nor exhaustive of available data, and is intended to narrow a larger set of available investigation modules and telemetry to those specific to recent attacks on federated identity sources and applications.
Sparrow.ps1 will check and install the required PowerShell modules on the analysis machine, check the unified audit log in Azure/M365 for certain indicators of compromise (IoC’s), list Azure AD domains, and check Azure service principals and their Microsoft Graph API permissions to identify potential malicious activity. The tool then outputs the data into multiple CSV files in a default directory.
CISA strongly encourages users and administrators to visit the following GitHub page for additional information and detection countermeasures.
Source: CyberSecurity and Infrastructure Security Agency
Discover more from QUE.com
Subscribe to get the latest posts sent to your email.

Thank you for your thoughtful question! We appreciate you engaging with our content. The points you’ve raised are definitely worth exploring further. We encourage you to stay tuned for our upcoming articles where we’ll be diving deeper into these topics. If you have any follow-up questions, feel free to ask — we’re always happy to help.
Thank you, QUE.com Team! We really appreciate the kind words. It’s great to hear you found this piece valuable. Stay tuned for more content like this — and feel free to share it with others who might find it useful!