Skip to main content
Midnight Blizzard: Malicious Entra App Registration and Service Principal Abuse operation cover
COMING SOONAdvancedPRO

Midnight Blizzard: Malicious Entra App Registration and Service Principal Abuse

A nation-state-style identity-plane intrusion that lives entirely in Microsoft Entra ID and Exchange Online. A low-and-slow password spray across rotating residential-proxy IPs lands on a legacy, no-MFA test account; from there the actor pivots into the application layer, creates a rogue user, registers a new malicious application and service principal, grants it the Office 365 Exchange Online full_access_as_app role plus EWS.AccessAsUser.All, adds a client secret for durable app-only access, and reads corporate mailboxes over Exchange Web Services with no user sign-in. Work the Entra sign-in audit, the application and service-principal lifecycle and role-assignment events, the credential change, and the EWS mailbox operations to reconstruct the chain and classify the key ATT&CK techniques.

1h 15m
8 tasks
150 points
Pro

Launches in 3 days

Sep 1, 2026

Tuesday, September 1, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

CloudSIEM

What you'll investigate

8 objectives unlock when this operation goes live.

1Incident brief
2Identify the foothold account
3Classify the initial-access technique
4Find the malicious application
5Name the role that opened every mailbox
6Find the durable-persistence credential
7Confirm the mailbox that was collected
8Classify the mailbox-collection technique

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Sep 1, 2026, you can jump straight in.

Get Started Free