Analytics BIOC
Informational
✕
Azure application credentials added
An identity added credentials to an Azure application.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Use Alternate Authentication Material (T1550)
Attacker's goals:
An attacker may add certificates or modify authentication methods of an application to authenticate as the application.
Investigative actions:
Check if the modified application is new to the organization. Check whether the account that modified the credentials is supposed to perform such actions. Check for possible logins from the application modified. Follow further actions done by the application.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Suspicious credential operation on an Azure application Medium (parent: Informational)
- Unusual certificate operation on an Azure application Low (parent: Informational)