wiz · Crawled Sep 1, 2026

How to Spot and Stop Rogue Device Joins

2 IoCs
Read original article ↗

AI Summary

Attackers are abusing Entra ID device registration functionality to establish persistent access by registering rogue devices using stolen credentials, often obtained via device code phishing. Traditionally, these attacks used predictable indicators like 'DESKTOP-XXXXXXXX' device names and specific User-Agent strings, but attackers are now adopting AI-generated, benign-looking identifiers such as 'Work PC' to evade static detection. The article highlights a shift toward behavioral detection methods, including identifying anomalies in device naming conventions and correlating device code phishing with subsequent device registration events to detect these stealthier attacks.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
IP 3[.]149[.]231[.]11 Details →
Domain lockwall[.]xyz Details →