Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1078 ✕

Download CSV Show ATT&CK heatmap
  • Azure AD account unlock/password reset attempt Informational Identity Threat Module, SaaS Threat Detection 1 variation

    An attempt to unlock an Azure AD identity or reset its password has occurred.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: AzureAD Audit Log
    Attacker's goals: An attacker may switch a valid account's password for persistence.
    Investigative actions: Check if the password reset is authorized. Check whether the user who reset the password is permitted to perform such actions. Check if the account is in the password reset group or is acting out of scope. Check whether the user has not completed the password reset and cancelled before successfully passing authentication methods. Follow further actions or suspicious logins from the target account.

    Variations

    Azure AD account unlock/successful password reset

    Low overridden

    An identity successfully reset or changed Azure AD password. overridden