Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0003 ✕

Download CSV Show ATT&CK heatmap
  • Identity assigned an Azure AD Administrator Role Informational Identity Threat Module, SaaS Threat Detection 2 variations

    An identity was assigned an Azure AD Administrator role.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003)
    Required data: AzureAD Audit Log
    Attacker's goals: An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.
    Investigative actions: Check if the added account is new to the organization. Check whether the account that added the account to the role is permitted to perform such actions. Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.

    Variations

    Identity assigned an Azure AD Administrator Role by an Application

    Medium overridden

    An identity was assigned an Azure AD Administrator role by an application. overridden

    Suspicious Azure AD Administrator Role assignment

    Low overridden

    An identity was assigned an Azure AD Administrator role. overridden