Analytics BIOC Informational

Suspicious Azure AD interactive sign-in using PowerShell

A user interactively logged in to Azure AD via PowerShell.

Module:
Identity Analytics
Data source:
AzureAD
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:

The attacker attempts to gain access to the organization's resources.

Investigative actions:

Analyze the actions taken by the user during the session and verify that this is a legitimate session. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Unusual Azure AD interactive sign-in using PowerShell Low (parent: Informational)