Cybersecurity and Infrastructure Security Agency (CISA) released a tool for detecting potentially malicious activities in Azure/Microsoft 365 environments. The Sparrow.ps1 script checks and installs the required. modules on the analysis machine, then check the unified audit log in MSAzure/M365 for certain indicators of compromise (IoCs), list Azure AD domains, and check Azure service principals and their Microsoft Graph API permissions to identify potential malicious activity. The tool is intended for use by incident responders and is narrowly focused on activity that is endemic to recent identity- and authentication-based attacks seen in multiple sectors.”]
Source: https://securityaffairs.co/wordpress/112751/security/cisa-azure-microsoft-365-detection-tool.html