Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0003 ✕ technique: T1098 ✕
Download CSV Show ATT&CK heatmapUnverified domain added to Azure AD Informational Identity Threat Module, SaaS Threat Detection 1 variation
A new unverified domain was added to Azure AD.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Account Manipulation: Additional Cloud Credentials (T1098.001)Required data: AzureAD Audit LogAttacker's goals: An attacker attempts to change Active Directory configuration for persistence or defense evasion.Investigative actions: Check if the new domain is known for the organization. Check whether the user changing the configuration is permitted. Monitor network activity to and from the added domain.Variations
Rare unverified domain addition to Azure AD
Low overridden
A new unverified domain was added to Azure AD. overridden