Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Azure account deletion by a non-standard account Low Identity Threat Module, SaaS Threat Detection 2 variations

    An Azure AD account deletion was performed by a user that doesn't typically delete users.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Account Access Removal (T1531)
    Required data: AzureAD Audit Log
    Attacker's goals: Interrupt availability and access to Azure by deleting access accounts.
    Investigative actions: Follow further actions by the initiator. Check what services, groups and applications are affected by the deleted user being removed. Check if the deleted user had a privileged role.

    Variations

    Azure account deletion by a non-standard account with high administrative activity

    Informational overridden

    An Azure AD account deletion was performed by an identity with high administrative activity that doesn't typically delete users. overridden

    A suspicious Azure account deletion by a non-standard account

    Medium overridden

    An Azure AD account deletion was performed by a user that doesn't typically delete users in a suspicious manner. overridden