Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1078 ✕

Download CSV Show ATT&CK heatmap
  • Short-lived Azure AD user account Informational Identity Threat Module, SaaS Threat Detection 1 variation

    An Azure AD user was created and deleted within a short period of time.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: AzureAD Audit Log
    Attacker's goals: Evasion using a valid account.
    Investigative actions: Check the user who created the account and verify the activity. Confirm that the account creation was not accidental.

    Variations

    Abnormal Short-lived Azure AD user account

    Low overridden

    An Azure AD user was created and deleted within a short period of time. overridden