Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • SSO with abnormal user agent Informational Identity Analytics 1 variation

    A user successfully authenticated via SSO with an abnormal user agent.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
    Required data: Okta AzureAD Azure SignIn Log Duo PingOne
    Attacker's goals: Use a legitimate user and authenticate via an SSO service to gain access to the network.
    Investigative actions: Confirm that the activity is benign (e.g. the user has really moved to a new user agent app). Follow actions and suspicious activities regarding the user.

    Variations

    SSO with an offensive user agent

    Low overridden

    A user successfully authenticated via SSO with an offensive user agent. overridden