Analytics BIOC
Informational
✕
User signed in to an application via Power Automate for the first time
A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD
ATT&CK tactics: Initial Access (TA0001) Exfiltration (TA0010)
ATT&CK techniques: Valid Accounts (T1078) Automated Exfiltration (T1020)
Attacker's goals:
Use automation flows to automate data exfiltration, C2 communication, lateral movement and evade DLP solutions.
Investigative actions:
Check if this was a desired behavior as part of the automation flow.* Analyze the actions taken by the user during the session and verify that this is a legitimate session. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Look for signs of different data exfiltration via email, shared links or uploads to online storage.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- User signed in to an uncommon application via Power Automate for the first time Low (parent: Informational)