Analytics BIOC Medium

Suspicious authentication with Azure Password Hash Sync user

Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user.

Module:
Identity Analytics
Data source:
AzureAD
ATT&CK tactics: Initial Access (TA0001) Defense Evasion (TA0005)
ATT&CK techniques: Valid Accounts (T1078) Modify Authentication Process: Hybrid Identity (T1556.007)
Attacker's goals:

The attacker may be attempting to exploit a PHS user, the attacker wants to escalate and abuse this user, to get access to all the user's hashes.

Investigative actions:

Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
1 Day