← Back to list

BTLO write-up: Vault

Q1) Utilizing Azure Sign-In logs, identify the individual associated with the login from the suspicious IP address “201.231.8.199” (Format…

Khalil Z. · 2025-10-25 22:32 · 0 claps · 1.3 min read
#btlo #vault #digital-forensics #cloud-computing
Open on Medium ↗
Wiki topics: ☁️ · DevOps & Cloud 🔒 · Cybersecurity

BTLO write-up: Vault

Q1) Utilizing Azure Sign-In logs, identify the individual associated with the login from the suspicious IP address “201.231.8.199” (Format: Name Name) (1 points)

Miriam Graham

Q2) Determine the User Principal Name (UPN) of the identified user (Format: mailbox@domain.com) (1 points)

MiriamG@bank.onmicrosoft.com

Q3) Ascertain whether the user is categorized as a member, guest, or an external account. (Hint: “User Type” field) (Format: xxxxxx) (1 points)

Member

Q4) Identify the token type issued to the user. (Hint: Refer to “Incoming Token Type”) (Format: Token Type) (1 points)

primaryRefreshToken

Q5) Was there any conditional access policy applied during sign-in? (Hint: “Conditional Access” column) (Format: yes/no) (1 points)

No

Q6) Investigate the Azure Key Vault Diagnostic logs to provide the subscription ID for the user who accessed key vaults in the Azure tenant (Format: ID) (1 points)

12az1234–04by-4e50–1e11-c00ae123d0bd

Q7) What is the name of the resource group where the key vaults were accessed? (Format: NAME) (1 points)

FINANCE

Q8) Determine the total number of Key Vaults present in the identified resource group (Format: Number of Key Vault) (3 points)

2

Q9) How many operations were executed using the application ID “04b07795–8ddb-461a-bbee-02f9e1bf7b46”? (Filter the results using the column “identity_claim_appid_g”) (Format: Number of Operations) (2 points)

14

Q10) Retrieve the application display name associated with the aforementioned application ID (Format: String) (3 points)

Microsoft Azure CLI

Q11) What is the User Agent associated with key-related operations performed by the above application? (Format: User-Agent String) (3 points)

azsdk-python-keyvault-secrets/4.7.0 Python/3.11.5 (Windows-10–10.0.19044-SP0)

Q12) In which specific key vault was a key identified? (Format: Key Vault Name) (2 points)

SALARY

Q13) Provide the name of the key present in the identified key vault (Format: Xxxxxxx) (2 points)

Payroll

Q14) Identify the secret name found in one of the key vaults (Format: Secret Name) (1 points)

Confidential

Q15) Determine the operation associated with the correlation ID “9c059db6-eb2f-4085–9979–4c94a5b19b0d” (Format: Operation Name) (1 points)

KeyList

Q16) What is the application name associated with the aforementioned operation? (Format: Application) (1 points)

Microsoft Azure PowerShell


메타데이터
post_id
a075f73cec41
slug
btlo-write-up-vault-a075f73cec41
url
https://medium.com/@Khalil.Z/btlo-write-up-vault-a075f73cec41
canonical_url
https://medium.com/@Khalil.Z/btlo-write-up-vault-a075f73cec41
author_url
https://medium.com/@Khalil.Z
status
ok
fetched_at
2026-06-16 19:09:56