Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • SSO with abnormal operating system Informational Identity Analytics

    A user successfully authenticated via SSO with an abnormal operating system.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
    Required data: AzureAD Okta OneLogin
    Attacker's goals: Use a legitimate user and authenticate via an SSO service to gain access to the network.
    Investigative actions: Confirm that the activity is benign (e.g. the user has really moved to a new operating system). Follow actions and suspicious activities regarding the user.