Analytics BIOC
Informational
✕
Suspicious SSO access from ASN
A suspicious SSO authentication was made by a user.
- Module:
- Identity Analytics
- Data source:
- AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
Attacker's goals:
Use an account that was possibly compromised to gain access to the network.
Investigative actions:
Confirm that the activity is benign (e.g. the user has switched locations and providers). Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Suspicious SSO access from ASN via a suspicious IP Low (parent: Informational)
- Google Workspace - Suspicious SSO access from ASN Informational