Analytics BIOC Informational

Azure application URI modification

An identity added or updated an Azure application's URI.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Use Alternate Authentication Material (T1550)
Attacker's goals:

An attacker may add certificates or modify authentication methods of an application to authenticate as the application.

Investigative actions:

Check whether the account that modified the URI is supposed to perform such actions. Check for possible logins from the application modified. Check for possible account consents or credential changes regarding the application. Follow further actions done by the application.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious Azure application URI modification Low (parent: Informational)