Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapInvalid SAML Detected Informational Identity Threat Module, SaaS Threat Detection 1 variation
A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Forge Web Credentials: SAML Tokens (T1606.002)Required data: AzureAD OktaDetector tags: Active Directory Federation Services AnalyticsAttacker's goals: An attacker might forge a valid SAML token to impersonate other user accounts. This is used to gain persistent, unauthorized access to cloud resources, and bypassing MFA.Investigative actions: Check for recent changes to the SAML signing certificate on both the Identity Provider and the Service Provider to rule out a configuration drift or expiration issue. Check for other correlated alerts on on-premises systems that may be related to the Golden SAML attack. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).Variations
Suspicious Invalid SAML Detected
Low overridden
A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack. overridden