Analytics BIOC
Medium
✕
Suspicious authentication with Azure Password Hash Sync user
Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user.
- Module:
- Identity Analytics
- Data source:
- AzureAD
ATT&CK tactics: Initial Access (TA0001) Defense Evasion (TA0005)
ATT&CK techniques: Valid Accounts (T1078) Modify Authentication Process: Hybrid Identity (T1556.007)
Attacker's goals:
The attacker may be attempting to exploit a PHS user, the attacker wants to escalate and abuse this user, to get access to all the user's hashes.
Investigative actions:
Follow further actions done by the account.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day