Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Successful unusual guest user invitation Informational Identity Threat Module, SaaS Threat Detection 1 variation

    An identity successfully invited a guest user to the tenant with unusual characteristics.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: AzureAD Audit Log
    Attacker's goals: An attacker can invite users to for evasion.
    Investigative actions: Check who is the invited guest user. Check whether the inviter is permitted to perform such actions. Check if the domain of the invited guest is allowed for invitations in the organization.

    Variations

    Rare successful guest invitation in the organization

    Low overridden

    An identity successfully invited a suspicious guest user to the tenant. overridden