Analytics BIOC Informational

Authentication method was added to Azure account

A new authentication method was added to an Azure AD user.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Modify Authentication Process (T1556)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:

Establish a backdoor for persistent access.

Investigative actions:

Review recent authentication attempts and access logs to detect any unauthorized activities or potential misuse of the newly added authentication method. Look for any unusual behavior originated from the suspected identity, and check if they're compromised.

Test period:
N/A (single event)
Deduplication:
5 Days