Analytics BIOC
Low
✕
SSO authentication attempt by a honey user
An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity.
- Module:
- Identity Analytics
- Data source:
- AzureAD, Okta, OneLogin, PingOne
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Detector tags: Honey User Analytics
Attacker's goals:
An attacker is attempting to gain unauthorized access by exploiting valid or stolen credentials.
Investigative actions:
Confirm that the alert was triggered by a honey user account. Check for other login attempts on different accounts from the same source IP. Analyze any subsequent actions performed by the user after the login attempt. Follow further actions performed by the user.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour
1 variation:
- Abnormal SSO authentication by a honey user Medium (parent: Low)