Analytics BIOC Informational

First SSO access from ASN for user

A user successfully authenticated via SSO with a new ASN.

Module:
Identity Analytics
Data source:
AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
Attacker's goals:

Use an account that was possibly compromised to gain access to the network.

Investigative actions:

Confirm that the activity is benign (e.g. the user has switched locations and providers). Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • First SSO access from ASN for user - suspicious characteristics detected Low (parent: Informational)
  • Google Workspace - First SSO access from ASN for user Informational