Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1078 ✕
Download CSV Show ATT&CK heatmapAzure service principal assigned app role Informational Identity Threat Module, SaaS Threat Detection
An identity assigned an app role (permissions) to a service principal.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004)ATT&CK techniques: Valid Accounts (T1078)Required data: AzureAD Audit LogAttacker's goals: An attacker may add roles to service principals that will allow them to access sensitive information and perform other actions.Investigative actions: Check if the added service principle is new to the organization. Check whether the account that added the app role is supposed to perform such actions. Check for possible logins and actions from the service principle with the role. Follow further actions done by the application and the assigner.