Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0003 ✕

Download CSV Show ATT&CK heatmap
  • SharePoint Site Collection admin group addition Informational Identity Threat Module, SaaS Threat Detection 2 variations

    A user made an addition to the site collection administrators group in SharePoint.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003)
    Required data: Office 365 Audit
    Attacker's goals: Elevate permissions and establish persistence.
    Investigative actions: Check the IP address from which the access originated. Verify the activity with the performing user. Follow further actions done by the account.

    Variations

    SharePoint site collection admin added to personal site

    Informational overridden

    A user was added as a site collection admin to a personal site, indicating that the user has accessed the SharePoint service for the first time. overridden

    Abnormal SharePoint Site Collection admin group addition

    Low overridden

    A user made an addition to the site collection administrators group in SharePoint. This user has not made any SharePoint site admin additions over the past 30 days. overridden