Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0001 ✕
Download CSV Show ATT&CK heatmapSuccessful universal authentication with suspicious features Informational Identity Analytics 4 variations
A universal authentication was flagged as suspicious based on anomalous features.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts (T1078)Attacker's goals: Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.Investigative actions: Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN.Variations
Successful universal authentication sign-in from a TOR exit node
Medium overridden
A successful sign-in from a TOR exit node in universal authentication. overridden
Successful universal authentication from a suspicious tunnel operator
Low overridden
A successful universal authentication was made through a suspicious or rarely seen tunnel operator. overridden
Suspicious successful universal authentication from ASN
Informational overridden
A successful universal authentication was made from a suspicious or previously unseen ASN. overridden
Successful universal authentication from a new country in organization
Informational overridden
A user authenticated in universal authentication from an unusual country that no one from this organization has connected from before in universal authentication. This may indicate the account was compromised. overridden