Analytics BIOC Informational

Granting Access to an Account

Azure access has been granted to an account.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006)
ATT&CK techniques: Valid Accounts (T1078) Unsecured Credentials (T1552) Modify Authentication Process (T1556) OS Credential Dumping (T1003) Brute Force (T1110) Forge Web Credentials (T1606)
Attacker's goals:

Gain unauthorized access to an account.* Gain access to sensitive data.

Investigative actions:

Check the account access logs to determine the source of the access.* Check the account activity logs to determine the purpose of the access.

Test period:
N/A (single event)
Deduplication:
5 Days