Analytics BIOC Low

VPN login by a service account

A service account attempted to log in to a VPN service.

Module:
Identity Analytics
Data source:
Palo Alto Networks Global Protect, Third-Party VPNs
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
Attacker's goals:

Use an account that was possibly compromised in the past to gain access to the network and access privileged resources.

Investigative actions:

See whether the service authentication was successful. Check whether the account has done any administrative actions it should not usually do. Look for more logins and authentications by the account throughout the network.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Rare VPN login by an administrative service account Medium (parent: Low)