Analytics BIOC Informational

A possible risky login to Azure

A risky sign-in attempt was observed in Azure.

Module:
Identity Analytics
Data source:
AzureAD
ATT&CK tactics: Initial Access (TA0001) Resource Development (TA0042)
ATT&CK techniques: Compromise Accounts (T1586) Valid Accounts (T1078)
Attacker's goals:

An attacker is attempting to compromise an Azure account by exploiting weak or guessed passwords for initial access.

Investigative actions:

Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Reach out to the user to confirm the legitimacy of the recent password reset activity. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Azure Risky Login with Suspicious Characteristics Low (parent: Informational)
  • Azure-Defined High-Risk Login Attempt Low (parent: Informational)