remediate-entra-credential-revoke
Installation
SKILL.md
remediate-entra-credential-revoke
What this closes
Pair skill for both shipped Entra detectors:
detect-entra-credential-addition— T1098.001 Additional Cloud Credentials (an attacker added a new key/password credential to a service principal or application)detect-entra-role-grant-escalation— T1098.003 Additional Cloud Roles (an attacker escalated an SP's app-role assignments)
Closes #155 phase 3 + the detection-side of #238. After this lands, the closed-loop matrix flips both Entra detection rows from amber → green. Ratio goes 5/11 → 7/11.
Why disable + triage (not auto-revoke)
The two Entra detectors fire on Graph audit log entries. They know:
- WHICH service principal was modified (
target.uid) - WHEN (
time) - WHAT operation (
api.operation, e.g.Update application -- Certificates and secrets management)