• Customers
Sign in

Integrations

Check out our evergrowing list of integrations

Fuse

From raw logs to enriched, correlated intelligence at the speed of ingestion

Detect

Stateful cloud detection with no
tradeoffs

Investigate

See how the attack began, what the adversary did, and where it could go

Respond

Act precisely.
Recover confidently

Stream Force

Build, run, and scale agentic security workflows

Have I Been Pwned? Detecting Entra ID Persistence Before Your SIEM Even Existed

Most detection content catches persistence techniques as they happen. But what if the attacker was already there before you connected your logs? CloudTwin™ analyzes Entra ID configuration state — not just log events — to answer the question every SOC team should be asking: "Have I been pwned?"

All Resources

Learn about cloud detection
and response

Upcoming Events

Meet our team at upcoming
expos and events

Blog

Insights, product updates, and security tips

Datasheets

Technical overviews and product specifications

Reports

Research, analysis, and industry findings

Webinars

Join our live event or watch on
demand

Watch on demand

You Can't Prompt Your Way Out of Bad Data: Why Context, Not Models, Wins in the Cloud

February 6, 2026

About Us

Get to know our story and team

Press

News, articles and press resources

Jobs

Join us, we’re hiring!

Contact Us

Get a Demo
Home
Resources
Tags

#

IdP

No items found.
Have I Been Pwned? Detecting Entra ID Persistence Before Your SIEM Even Existed
Cloud Detection & Response
Have I Been Pwned? Detecting Entra ID Persistence Before Your SIEM Even Existed
Most detection content catches persistence techniques as they happen. But what if the attacker was already there before you connected your logs? CloudTwin™ analyzes Entra ID configuration state — not just log events — to answer the question every SOC team should be asking: "Have I been pwned?"
Petr Zuzanov
May 14, 2026
12
min
SaaS-Sourced Threat Detections: Enhancing Cloud Visibility and Precision Response
Product
SaaS-Sourced Threat Detections: Enhancing Cloud Visibility and Precision Response
Today, we’re excited to roll out our SaaS-sourced threat detections, built to give SecOps teams complete visibility across the services powering their cloud. Stream’s SaaS detections extend our end-to-end visibility beyond all cloud layers to include SaaS as part of our commitment to delivering full-spectrum coverage in a single platform.
Stream Team
Aug 7, 2025
5
min
Browse other tags
AI SOC
Atlantis
AWS
CDR
CloudTwin
CNAPP
Compliance
Compute
Cost Optimization
Data Security
Disaster Recovery
DSPM
EDR
Flow Logs
Gartner
GitHub
Kubernetes
Networking
Permissions
re:Invent
Reliability
Resilience
Secrets
Shift-left
SIEM
SOAR
Stream Traps
Sustainability
Terraform
Troubleshooting
XDR

Product

FuseDetectInvestigateRespondScale with AI

Resources

Book a demoCustomersBlogWebinarsCloudWiki

Product

About usBecome a PartnerPressJobsContact us

© StreamSec ltd.

Copyright PolicyTerms of UsePrivacy