Analytics BIOC
Informational
✕
Azure account creation by a non-standard account
An Azure AD account creation was performed by a user that doesn't typically create users.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Create Account (T1136)
Attacker's goals:
Create a backdoor account for later access to Azure AD or Azure resources, or delete evidence of such an account.
Investigative actions:
Follow further actions by the initiator. Check for new resource creations by the new user. Check if the new user was added to a privileged role. Follow further actions done by the new user.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual Azure account creation by a non-standard account Low (parent: Informational)