Intune as a Lateral Movement Plane: Detecting Red Team Abuse of Device Script Deployment
Red teams are pivoting through Intune to get fleet-wide SYSTEM execution after a single privileged Entra account. Here’s what the abuse looks like in the audit log, what tuning the first detection needs, and where most SOCs miss it.