Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • An Azure identity performed multiple actions that were denied Informational Cloud 3 variations

    An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    5 Days
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Account Discovery (T1087) Permission Groups Discovery (T1069)
    Required data: Azure Audit Log Microsoft Graph Logs
    Detector tags: Microsoft Graph Activity Logs
    Attacker's goals: Execute various of commands to explore the cloud environment.
    Investigative actions: Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

    Variations

    An Azure application attempted multiple actions on resources that were denied

    Medium overridden

    An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. overridden

    An Azure identity attempted multiple actions on resources that were denied

    Low overridden

    An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. overridden

    An Azure application performed multiple actions that were denied

    Low overridden

    An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. overridden