Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0040 ✕

Download CSV Show ATT&CK heatmap
  • Multiple Azure AD admin role removals Low Identity Threat Module, SaaS Threat Detection

    An Azure AD identity removed multiple administrators from their roles.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    3 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Account Access Removal (T1531)
    Required data: AzureAD Audit Log
    Attacker's goals: An attacker may want to lock out an organization and retain sole access.
    Investigative actions: Check if the identity performing the actions was authorized to perform them. Check what roles the users were removed from. Check whether the identity is a newly added admin. Check if the identity is operating in its usual manner (location, time, operations)* Check if the identity performed additional operations in the cloud environment that might be malicious.