Analytics BIOC Informational

SaaS suspicious external domain user activity

An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs, Office 365 Audit
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: External Remote Services (T1133)
Attacker's goals:

Gain their initial foothold within the organization and explore the environment to achieve their target.

Investigative actions:

Investigate the external domain name. Check the identity activity in the organization.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious external user activity detected from a domain first seen in the organization Low (parent: Informational)