Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • An inactive user attempted to authenticate Informational Identity Analytics 3 variations

    A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004)
    Attacker's goals: Use an account that was possibly compromised in the past to gain access to the network.
    Investigative actions: Confirm that the activity is benign (e.g. the user returned from a long leave of absence).

    Variations

    Successful authentication by an inactive user from a risky IP address

    Low overridden

    A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication. overridden

    An inactive user attempted to authenticate from a risky IP address

    Low overridden

    A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication. overridden

    Successful authentication by an inactive user

    Informational overridden

    A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication. overridden