Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Suspicious SSO access from ASN Informational Identity Analytics 2 variations

    A suspicious SSO authentication was made by a user.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
    Required data: AzureAD Azure SignIn Log Idira Duo Google Workspace Authentication Okta OneLogin PingOne
    Attacker's goals: Use an account that was possibly compromised to gain access to the network.
    Investigative actions: Confirm that the activity is benign (e.g. the user has switched locations and providers). Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user.

    Variations

    Suspicious SSO access from ASN via a suspicious IP

    Low overridden

    A suspicious SSO authentication was made by a user. overridden

    Google Workspace - Suspicious SSO access from ASN

    Informational overridden

    A suspicious SSO authentication was made by a user. overridden