Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • First connection from a country in organization Informational Identity Analytics 2 variations

    A user connected to an SSO service from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
    ATT&CK techniques: Compromise Accounts (T1586) Brute Force: Password Guessing (T1110.001)
    Required data: AzureAD Azure SignIn Log Idira Duo Okta OneLogin PingOne
    Attacker's goals: Gain user-account credentials.
    Investigative actions: Check if the user is currently located in the aforementioned country, or routed its traffic there via a VPN.

    Variations

    First connection from a country in organization via a suspicious IP

    Low overridden

    A user connected to an SSO service from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised. overridden

    First successful SSO connection from a country in organization

    Informational overridden

    A user successfully connected from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised. overridden