Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0042 ✕ technique: T1586 ✕
Download CSV Show ATT&CK heatmapA possible risky login to Azure Informational Identity Analytics 2 variations
A risky sign-in attempt was observed in Azure.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001) Resource Development (TA0042)ATT&CK techniques: Compromise Accounts (T1586) Valid Accounts (T1078)Required data: AzureADAttacker's goals: An attacker is attempting to compromise an Azure account by exploiting weak or guessed passwords for initial access.Investigative actions: Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Reach out to the user to confirm the legitimacy of the recent password reset activity. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.Variations
Azure Risky Login with Suspicious Characteristics
Low overridden
A risky sign-in attempt was observed in Azure. overridden
Azure-Defined High-Risk Login Attempt
Low overridden
A risky sign-in attempt was observed in Azure. overridden