Incident Response Lab: Azure Storage Breach Containment
Investigate and contain credential abuse against Azure Storage accounts, pivoting from unified audit logs to live containment with Logic Apps and Defender for Cloud.
FIRST OBJECTIVES
- Collect incident artifacts from Azure Activity and Storage logs
- Replay the intrusion timeline entirely with KQL queries
- Deploy a Logic App playbook that locks compromised storage keys


