Analytics BIOC Informational

Penetration testing tool activity attempt

A SaaS API was invoked by a penetration testing tool.

Module:
Identity Analytics
Data source:
Office 365 Audit
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Serverless Execution (T1648)
Attacker's goals:

Usage of known tools and frameworks.

Investigative actions:

Check if there is an active PT test ongoing.

Test period:
N/A (single event)
Deduplication:
2 Days
1 variation:
  • Penetration testing tool activity attempt Medium (parent: Informational)