Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1078 ✕

Download CSV Show ATT&CK heatmap
  • First SSO access from ASN for user Informational Identity Analytics 2 variations

    A user successfully authenticated via SSO with a new ASN.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
    Required data: AzureAD Azure SignIn Log Idira Duo Google Workspace Authentication Okta OneLogin PingOne
    Attacker's goals: Use an account that was possibly compromised to gain access to the network.
    Investigative actions: Confirm that the activity is benign (e.g. the user has switched locations and providers). Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user.

    Variations

    First SSO access from ASN for user - suspicious characteristics detected

    Low overridden

    First SSO access from ASN for user that shows suspicious characteristics. overridden

    Google Workspace - First SSO access from ASN for user

    Informational overridden

    A user successfully authenticated via SSO with a new ASN. overridden