Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0003 ✕
Download CSV Show ATT&CK heatmapAuthentication method added to an Azure account Informational Identity Threat Module, SaaS Threat Detection 2 variations
An identity attempted to add an Azure authentication method.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Valid Accounts (T1078)Required data: AzureAD Audit LogAttacker's goals: An attacker can add an authentication method to an account, so they can have later access to the tenant and resources.Investigative actions: Check if the authentication method is legitimate in the organization. Check whether the identity is permitted to perform such actions. Follow the account for possible suspicious or unusual logins.Variations
Suspicious authentication method addition to privileged Azure account
Medium overridden
A privileged user added an Azure authentication method. overridden
Suspicious authentication method addition to Azure account
Low overridden
An identity added an Azure authentication method. overridden