Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAzure Temporary Access Pass (TAP) registered to an account Informational Identity Threat Module, SaaS Threat Detection 2 variations
An identity registered an Azure Temporary Access Pass (TAP) to an account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005) Privilege Escalation (TA0004)ATT&CK techniques: Valid Accounts (T1078)Required data: AzureAD Audit LogAttacker's goals: A TAP can allow setting of other authentication methods and can be used as an initial replacement of a multifactor authentication.Investigative actions: Check if the account that got the TAP should get it. Check whether the account that registered the TAP is supposed to perform such actions. Check if the TAP was registered to a privileged account. Follow further actions done by the initiator and the account with the TAP.Variations
Azure Temporary Access Pass (TAP) registered to a privileged account
Medium overridden
An identity registered an Azure Temporary Access Pass (TAP) to an account. overridden
Abnormal Azure Temporary Access Pass (TAP) account registration
Low overridden
An identity registered an Azure Temporary Access Pass (TAP) to an account. overridden