Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0003 ✕

Download CSV Show ATT&CK heatmap
  • Authentication method added to an Azure account Informational Identity Threat Module, SaaS Threat Detection 2 variations

    An identity attempted to add an Azure authentication method.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: AzureAD Audit Log
    Attacker's goals: An attacker can add an authentication method to an account, so they can have later access to the tenant and resources.
    Investigative actions: Check if the authentication method is legitimate in the organization. Check whether the identity is permitted to perform such actions. Follow the account for possible suspicious or unusual logins.

    Variations

    Suspicious authentication method addition to privileged Azure account

    Medium overridden

    A privileged user added an Azure authentication method. overridden

    Suspicious authentication method addition to Azure account

    Low overridden

    An identity added an Azure authentication method. overridden