Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Impossible traveler - SSO Low Identity Analytics 3 variations

    User connected from several remote countries, at least one of which is not commonly used in the organization, within a short period of time. This may indicate the account is compromised.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    6 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
    ATT&CK techniques: Compromise Accounts (T1586) Brute Force: Password Guessing (T1110.001)
    Required data: AzureAD Azure SignIn Log Idira Duo Okta OneLogin PingOne
    Attacker's goals: Gain user-account credentials.
    Investigative actions: Check if the user routed their traffic via a VPN, or shared their credentials with a remote employee.

    Variations

    Impossible traveler - non-interactive SSO authentication

    Informational overridden

    User connected from several remote countries, at least one of which is not commonly used in the organization, within a short period of time. This may indicate the account is compromised. overridden

    Possible Impossible traveler via SSO

    Informational overridden

    User connected from several remote countries, at least one of which is not commonly used in the organization, within a short period of time. This may indicate the account is compromised. overridden

    SSO impossible traveler from a VPN or proxy

    Informational overridden

    User connected from several remote countries, at least one of which is not commonly used in the organization, within a short period of time. This may indicate the account is compromised. overridden