Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1098 ✕

Download CSV Show ATT&CK heatmap
  • Unverified domain added to Azure AD Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A new unverified domain was added to Azure AD.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation: Additional Cloud Credentials (T1098.001)
    Required data: AzureAD Audit Log
    Attacker's goals: An attacker attempts to change Active Directory configuration for persistence or defense evasion.
    Investigative actions: Check if the new domain is known for the organization. Check whether the user changing the configuration is permitted. Monitor network activity to and from the added domain.

    Variations

    Rare unverified domain addition to Azure AD

    Low overridden

    A new unverified domain was added to Azure AD. overridden