Tool
Azure PowerShell
- First Reported
- Sep 23, 2026
- Latest Reported
- Sep 23, 2026
Reported Context (1)
- For authentication, the script tries the Azure CLI first, which avoids creating a new sign-in event, and falls back to device code flow with Azure PowerShell’s client ID, which is pre-consented in most tenants. TrustSink Uses a Rogue Entra Authentication Provider to Steal Passwords
People (1)
MITRE ATT&CK (3)
Vendors (1)
Products (3)
Tools (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.