Analytics BIOC Informational

Successful unusual guest user invitation

An identity successfully invited a guest user to the tenant with unusual characteristics.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:

An attacker can invite users to for evasion.

Investigative actions:

Check who is the invited guest user. Check whether the inviter is permitted to perform such actions. Check if the domain of the invited guest is allowed for invitations in the organization.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Rare successful guest invitation in the organization Low (parent: Informational)