
Midnight Blizzard: Malicious Entra App Registration and Service Principal Abuse
A nation-state-style identity-plane intrusion that lives entirely in Microsoft Entra ID and Exchange Online. A low-and-slow password spray across rotating residential-proxy IPs lands on a legacy, no-MFA test account; from there the actor pivots into the application layer, creates a rogue user, registers a new malicious application and service principal, grants it the Office 365 Exchange Online full_access_as_app role plus EWS.AccessAsUser.All, adds a client secret for durable app-only access, and reads corporate mailboxes over Exchange Web Services with no user sign-in. Work the Entra sign-in audit, the application and service-principal lifecycle and role-assignment events, the credential change, and the EWS mailbox operations to reconstruct the chain and classify the key ATT&CK techniques.
Launches in 3 days
Tuesday, September 1, 2026 at 9:00 AM
Pro unlocks this operation at launch.
Training Tools
What you'll investigate
8 objectives unlock when this operation goes live.
Be first when it launches
Create your account and grab Pro before launch. The moment this operation goes live on Sep 1, 2026, you can jump straight in.
Get Started Free