Analytics BIOC
Informational
✕
Suspicious Azure AD interactive sign-in using PowerShell
A user interactively logged in to Azure AD via PowerShell.
- Module:
- Identity Analytics
- Data source:
- AzureAD
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:
The attacker attempts to gain access to the organization's resources.
Investigative actions:
Analyze the actions taken by the user during the session and verify that this is a legitimate session. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual Azure AD interactive sign-in using PowerShell Low (parent: Informational)