Analytics BIOC
Informational
✕
Owner added to Azure application
An identity was added as an owner to an Azure application.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal Application Access Token (T1528)
Attacker's goals:
An attacker may add owners to an application to authenticate as the application later on and access resources.
Investigative actions:
Check if the added account is new to the organization. Check whether the account that added the new owner is supposed to perform such actions. Check for possible logins from the application modified. Follow further actions done by the application.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day