Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Remote usage of an Azure Service Principal token Informational Cloud 2 variations

    An Azure Service Principal token was used externally of the cloud environment.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Steal Application Access Token (T1528) Unsecured Credentials (T1552)
    Required data: Azure Audit Log
    Attacker's goals: Exfiltrate valid token and abuse it remotely.
    Investigative actions: Verify whether the service principal should be used remotely. Check what API calls were executed by the service principal. Determine whether the service principal is compromised.

    Variations

    Remote usage of an Azure Service Principal token from an unusual ASN

    High overridden

    An Azure Service Principal token was used externally of the cloud environment. overridden

    Remote usage of an Azure Service Principal token from an unusual IP

    Medium overridden

    An Azure Service Principal token was used externally of the cloud environment. overridden