Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1526 ✕

Download CSV Show ATT&CK heatmap
  • Unusual resource access by Azure application Informational Cloud 1 variation

    An Azure application had interacted with an unusual resource using the Microsoft Graph API.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Cloud Service Discovery (T1526)
    Required data: Azure Audit Log Microsoft Graph Logs
    Detector tags: Microsoft Graph Activity Logs
    Attacker's goals: Abuse applications to gain access to the Azure tenant.
    Investigative actions: Verify whether the application is intended to use the resource in question. Investigate any unusual activity originating from the application.

    Variations

    Suspicious resource access by Azure application

    Low overridden

    An Azure application had interacted with an unusual resource using the Microsoft Graph API. overridden