Analytics BIOC
Informational
✕
Azure application consent
An identity consented permissions to an application.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006)
ATT&CK techniques: Phishing (T1566) Phishing: Spearphishing Link (T1566.002) Steal Application Access Token (T1528) Trusted Relationship (T1199)
Attacker's goals:
Get access to credentials, data or an organization via applications with sufficient permissions.
Investigative actions:
Follow further actions by the consenting user. Check for new resource creations by the new user. Check how the consenting user got to the application. Verify the application creators. Check what permissions the application requested. Check for possible phishing in the organization.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- First seen Azure admin consent to an application Low (parent: Informational)