Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAn Azure identity performed multiple actions that were denied Informational Cloud 3 variations
An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 10 Minutes
- Deduplication:
- 5 Days
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Account Discovery (T1087) Permission Groups Discovery (T1069)Required data: Azure Audit Log Microsoft Graph LogsDetector tags: Microsoft Graph Activity LogsAttacker's goals: Execute various of commands to explore the cloud environment.Investigative actions: Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.Variations
An Azure application attempted multiple actions on resources that were denied
Medium overridden
An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. overridden
An Azure identity attempted multiple actions on resources that were denied
Low overridden
An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. overridden
An Azure application performed multiple actions that were denied
Low overridden
An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. overridden