Analytics BIOC Low

First Azure AD PowerShell operation for a user

A user performed an Azure AD operation using a PowerShell user-agent for the first time.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:

Achieve initial access to a company's resources.

Investigative actions:

Follow the actions the user performed using PowerShell. Confirm with the user that the action was intended.

Test period:
N/A (single event)
Deduplication:
1 Day