Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1606 ✕

Download CSV Show ATT&CK heatmap
  • Invalid SAML Detected Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Forge Web Credentials: SAML Tokens (T1606.002)
    Required data: AzureAD Okta
    Detector tags: Active Directory Federation Services Analytics
    Attacker's goals: An attacker might forge a valid SAML token to impersonate other user accounts. This is used to gain persistent, unauthorized access to cloud resources, and bypassing MFA.
    Investigative actions: Check for recent changes to the SAML signing certificate on both the Identity Provider and the Service Provider to rule out a configuration drift or expiration issue. Check for other correlated alerts on on-premises systems that may be related to the Golden SAML attack. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

    Variations

    Suspicious Invalid SAML Detected

    Low overridden

    A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack. overridden