Analytics Alerts
Browse the Cortex analytics alert reference.
2 alerts match the current filters. tactic: TA0002 ✕ technique: T1098 ✕
Download CSV Show ATT&CK heatmapAzure VM extension abuse attempt Informational Cloud 1 variation
A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Persistence (TA0003) Defense Evasion (TA0005)ATT&CK techniques: Cloud Administration Command (T1651) Command and Scripting Interpreter: Cloud API (T1059.009) Account Manipulation (T1098) Impair Defenses: Disable or Modify Tools (T1562.001)Required data: Azure Audit LogAttacker's goals: Execute arbitrary code on VMs without network access (CustomScriptExtension). Gain persistent access by resetting local admin passwords (VMAccessExtension). Disable antimalware to deploy malware undetected (IaaSAntimalware deletion).Investigative actions: Identify the extension type involved (CustomScriptExtension, VMAccessExtension, IaaSAntimalware). For CustomScriptExtension: review the script payload executed on the VM. For VMAccessExtension: check if local admin credentials were reset and audit subsequent logins. For IaaSAntimalware deletion: verify the virtual machine audit log after the extension was removed. Verify whether the identity performing the operation is authorized to manage VM extensions. Check for correlated suspicious activity such as new role assignments or lateral movement.Variations
Unusual azure VM extension abuse
Low overridden
A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. overridden
Okta API Token Created Informational Identity Threat Module, SaaS Threat Detection 1 variation
A user created a new API token in Okta.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004) Execution (TA0002) Persistence (TA0003)ATT&CK techniques: Access Token Manipulation: Make and Impersonate Token (T1134.003) Command and Scripting Interpreter: Cloud API (T1059.009) Account Manipulation: Additional Cloud Credentials (T1098.001)Required data: Okta Audit LogDetector tags: Okta Audit AnalyticsAttacker's goals: An attacker's goal is to gain unauthorized access, compromise user accounts, and perform malicious actions within an organization's systems, potentially leading to data breaches, account takeovers, and the escalation of privileges.Investigative actions: Review the actions taken by the user that created the token. Follow the operations made using this API token by the ID token. Contact the user who created the API token and ensure that the API token is needed.Variations
An Okta API token was generated with suspicious characteristics
Low overridden
A user created a new API token in Okta with suspicious conditions. overridden