Splunk published attack simulation datasets showing two Microsoft Entra ID account-manipulation scenarios tied to MITRE ATT&CK T1098. In one case, an attacker changes an Azure AD guest account’s UserType from Guest to Member, removing the normal tenant-resource restrictions applied to guest identities and potentially expanding access for persistence. The dataset is based on Azure Audit logs and includes a benign user profile update that changes MobilePhone without modifying UserType, allowing defenders to test detection specificity.
A second dataset models persistence through T1098.001 by adding a federated identity credential to an Entra ID service principal. The simulated change establishes trust with an external GitHub Actions OIDC issuer and repository outside the tenant’s control, creating a path for unauthorized workload authentication. That dataset also includes a benign service principal update that changes only DisplayName, helping analysts distinguish malicious federated credential additions from routine administrative activity during replay and validation in Splunk environments.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Research published an attack simulation dataset in which an Azure Entra ID guest account has its UserType changed from Guest to Member, removing normal guest tenant-resource restrictions. The Azure Audit log dataset is intended for replay or manual import into Splunk Attack Range environments and maps to MITRE ATT&CK T1098.
Splunk Research published an attack simulation dataset showing a federated identity credential added to a Microsoft Entra ID service principal, configured to an external GitHub Actions OIDC issuer and repository not controlled by the tenant. The dataset is presented as Azure Audit log data for testing and replay and maps to MITRE ATT&CK T1098.001.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.