Analytics BIOC Informational

Azure account creation by a non-standard account

An Azure AD account creation was performed by a user that doesn't typically create users.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Create Account (T1136)
Attacker's goals:

Create a backdoor account for later access to Azure AD or Azure resources, or delete evidence of such an account.

Investigative actions:

Follow further actions by the initiator. Check for new resource creations by the new user. Check if the new user was added to a privileged role. Follow further actions done by the new user.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Unusual Azure account creation by a non-standard account Low (parent: Informational)