Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Azure account creation by a non-standard account Informational Identity Threat Module, SaaS Threat Detection 1 variation

    An Azure AD account creation was performed by a user that doesn't typically create users.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation (T1098) Create Account (T1136)
    Required data: AzureAD Audit Log
    Attacker's goals: Create a backdoor account for later access to Azure AD or Azure resources, or delete evidence of such an account.
    Investigative actions: Follow further actions by the initiator. Check for new resource creations by the new user. Check if the new user was added to a privileged role. Follow further actions done by the new user.

    Variations

    Unusual Azure account creation by a non-standard account

    Low overridden

    An Azure AD account creation was performed by a user that doesn't typically create users. overridden