Analytics rules — August 23, 2026
166 files changed, 475 insertions, 179 deletions — view the commit on the mirror.
Four universal authentication detectors added; 124 identity detectors gain the SaaS Threat Detection module
- Four new Identity Analytics detectors cover a newly named event class, universal authentication: brute force, password spray, inactive-user authentication, and successful sign-in with suspicious features.
- 124 detectors were reassigned, adding
SaaS Threat DetectionalongsideIdentity Threat Module— 103 identity detectors and 21 that also carryEmail. - 36 cloud detectors gained a
detector_tagsgrouping for the first time: Cloud Log Tampering Analytics, OCI Analytics, and SSM Remote Management Analytics. - One rule was renamed, one variation was withdrawn, and two deduplication periods were retuned. Nothing else changed.
Highlights
-
Universal authentication arrives as its own detection surface
Four rules, all Identity Analytics with a 14-day activation period, hunt brute force and password spray over a 1-hour test period plus two single-event detections for inactive users and suspicious sign-in features.
-
124 detectors now name SaaS Threat Detection as a detection module
Every one of them kept Identity Threat Module and added SaaS Threat Detection next to it, so this widens which module each detector is listed under rather than moving any of them.
-
The Email module set was extended the same way
21 Exchange, DLP and mail-flow detectors went from `Identity Threat Module, Email` to `Identity Threat Module, SaaS Threat Detection, Email`.
-
Three new detector tag groupings appear across cloud detectors
19 detectors were tagged Cloud Log Tampering Analytics, 11 OCI Analytics, and 6 SSM Remote Management Analytics, in each case added to a previously empty or existing tag list.
-
The rare internal firewall vulnerability rule was renamed to name NGFW explicitly
"Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert" became "Analytics enhanced NGFW Threat Alert - …", changing the file path as well as the rule and variation names.
-
AWS SSM parameters retrieval lost a variation and deduplicates far more often
The Informational "Unusual AWS SSM parameters retrieval" variation was removed outright and does not reappear elsewhere, while the deduplication period dropped from 5 Days to 1 Day.
Changes
166 files listed, 7 written up and shaded below.
-
▸ ▾ A cloud identity executed an API call from an unusual country modified +1 −1
analytics/a-cloud-identity-executed-an-api-call-from-an-unusual-countryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Access sensitive resources and gain high privileges.","attackers_goals": "Access sensitive resources and gain high privileges.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A cloud identity that normally connects from a limited set of countries connected from a new country for the first time.","description": "A cloud identity that normally connects from a limited set of countries connected from a new country for the first time.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "Kubernetes - API","detector_tags": "Kubernetes - API, OCI Analytics","investigative_actions": "Check if the identity routed their traffic via a VPN or shared their credentials with a remote employee.","investigative_actions": "Check if the identity routed their traffic via a VPN or shared their credentials with a remote employee.","name": "A cloud identity executed an API call from an unusual country","name": "A cloud identity executed an API call from an unusual country","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log","Gcp Audit Log","Kubernetes Audit Logs""Kubernetes Audit Logs"],],Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "Access sensitive resources and gain high privileges.", "deduplication_period": "1 Day", "description": "A cloud identity that normally connects from a limited set of countries connected from a new country for the first time.", "detection_modules": "Cloud", - "detector_tags": "Kubernetes - API", + "detector_tags": "Kubernetes - API, OCI Analytics", "investigative_actions": "Check if the identity routed their traffic via a VPN or shared their credentials with a remote employee.", "name": "A cloud identity executed an API call from an unusual country", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log", "Kubernetes Audit Logs" ], -
▸ ▾ A domain was added to the trusted domains list modified +1 −1
analytics/a-domain-was-added-to-the-trusted-domains-listRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Domain or Tenant Policy Modification: Trust Modification (T1484.002)""Domain or Tenant Policy Modification: Trust Modification (T1484.002)"],],"attackers_goals": "An adversary may add a trusted domain to collect and exfiltrate data from their target's organization with less restrictive security controls.","attackers_goals": "An adversary may add a trusted domain to collect and exfiltrate data from their target's organization with less restrictive security controls.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A domain was added to the Google Workspace trusted domains list.","description": "A domain was added to the Google Workspace trusted domains list.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate the new domain in the trusted domains list. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate the new domain in the trusted domains list. Follow further actions done by the account.","name": "A domain was added to the trusted domains list","name": "A domain was added to the trusted domains list","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Domain or Tenant Policy Modification: Trust Modification (T1484.002)" ], "attackers_goals": "An adversary may add a trusted domain to collect and exfiltrate data from their target's organization with less restrictive security controls.", "deduplication_period": "5 Days", "description": "A domain was added to the Google Workspace trusted domains list.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate the new domain in the trusted domains list. Follow further actions done by the account.", "name": "A domain was added to the trusted domains list", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ A GCP service account was delegated domain-wide authority in Google Workspace modified +1 −1
analytics/a-gcp-service-account-was-delegated-domain-wide-authority-in-google-workspaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Domain or Tenant Policy Modification (T1484)""Domain or Tenant Policy Modification (T1484)"],],"attackers_goals": "Malicious Apps can be used to access the organization's Google data.","attackers_goals": "Malicious Apps can be used to access the organization's Google data.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "A Google Workspace admin has enabled domain-wide delegation to a GCP service account.","description": "A Google Workspace admin has enabled domain-wide delegation to a GCP service account.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.","name": "A GCP service account was delegated domain-wide authority in Google Workspace","name": "A GCP service account was delegated domain-wide authority in Google Workspace","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Domain or Tenant Policy Modification (T1484)" ], "attackers_goals": "Malicious Apps can be used to access the organization's Google data.", "deduplication_period": "2 Days", "description": "A Google Workspace admin has enabled domain-wide delegation to a GCP service account.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.", "name": "A GCP service account was delegated domain-wide authority in Google Workspace", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ A Google Workspace identity created, assigned or modified a role modified +1 −1
analytics/a-google-workspace-identity-created-assigned-or-modified-a-roleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An adversary may create, assign or modify a role to elevate the permissions of other user accounts and persist in their target's environment.","attackers_goals": "An adversary may create, assign or modify a role to elevate the permissions of other user accounts and persist in their target's environment.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "A Google Workspace identity created, assigned or modified a delegated admin role.","description": "A Google Workspace identity created, assigned or modified a delegated admin role.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check the identity's role designation in the organization. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check the identity's role designation in the organization. Follow further actions done by the account.","name": "A Google Workspace identity created, assigned or modified a role","name": "A Google Workspace identity created, assigned or modified a role","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An adversary may create, assign or modify a role to elevate the permissions of other user accounts and persist in their target's environment.", "deduplication_period": "2 Days", "description": "A Google Workspace identity created, assigned or modified a delegated admin role.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check the identity's role designation in the organization. Follow further actions done by the account.", "name": "A Google Workspace identity created, assigned or modified a role", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A Google Workspace identity performed an unusual admin console activity modified +1 −1
analytics/a-google-workspace-identity-performed-an-unusual-admin-console-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "To do.","attackers_goals": "To do.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "A Google Workspace identity performed an admin console activity for the first time.","description": "A Google Workspace identity performed an admin console activity for the first time.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the changes that were made look suspicious. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the changes that were made look suspicious. Follow further actions done by the account.","name": "A Google Workspace identity performed an unusual admin console activity","name": "A Google Workspace identity performed an unusual admin console activity","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "To do.", "deduplication_period": "2 Days", "description": "A Google Workspace identity performed an admin console activity for the first time.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the changes that were made look suspicious. Follow further actions done by the account.", "name": "A Google Workspace identity performed an unusual admin console activity", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A Google Workspace identity used the security investigation tool modified +1 −1
analytics/a-google-workspace-identity-used-the-security-investigation-toolRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Data from Information Repositories (T1213)","Data from Information Repositories (T1213)","Email Collection (T1114)""Email Collection (T1114)"],],"attackers_goals": "Access sensitive data.","attackers_goals": "Access sensitive data.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data.","description": "A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Determine what data was accessed using the security investigation tool.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Determine what data was accessed using the security investigation tool.","name": "A Google Workspace identity used the security investigation tool","name": "A Google Workspace identity used the security investigation tool","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Data from Information Repositories (T1213)", "Email Collection (T1114)" ], "attackers_goals": "Access sensitive data.", "deduplication_period": "1 Day", "description": "A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Determine what data was accessed using the security investigation tool.", "name": "A Google Workspace identity used the security investigation tool", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A Google Workspace Role privilege was deleted modified +1 −1
analytics/a-google-workspace-role-privilege-was-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Impact (TA0040)""Impact (TA0040)"],],"attack_techniques": ["attack_techniques": ["Account Access Removal (T1531)""Account Access Removal (T1531)"],],"attackers_goals": "Gain access to sensitive data stored in the workspace. Gain elevated privileges in the workspace.","attackers_goals": "Gain access to sensitive data stored in the workspace. Gain elevated privileges in the workspace.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A privilege was removed from a Google Workspace Role, This could potentially affect the access to services and data in the organization.","description": "A privilege was removed from a Google Workspace Role, This could potentially affect the access to services and data in the organization.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Investigate who was assigned the deleted role privilege. Verify if the role privilege was deleted intentionally.","investigative_actions": "Investigate who was assigned the deleted role privilege. Verify if the role privilege was deleted intentionally.","name": "A Google Workspace Role privilege was deleted","name": "A Google Workspace Role privilege was deleted","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Impact (TA0040)" ], "attack_techniques": [ "Account Access Removal (T1531)" ], "attackers_goals": "Gain access to sensitive data stored in the workspace. Gain elevated privileges in the workspace.", "deduplication_period": "5 Days", "description": "A privilege was removed from a Google Workspace Role, This could potentially affect the access to services and data in the organization.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Investigate who was assigned the deleted role privilege. Verify if the role privilege was deleted intentionally.", "name": "A Google Workspace Role privilege was deleted", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A Google Workspace service was configured as unrestricted modified +1 −1
analytics/a-google-workspace-service-was-configured-as-unrestrictedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Domain or Tenant Policy Modification (T1484)""Domain or Tenant Policy Modification (T1484)"],],"attackers_goals": "Malicious apps can be used to access the organization's Google data.","attackers_goals": "Malicious apps can be used to access the organization's Google data.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services.","description": "An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.","name": "A Google Workspace service was configured as unrestricted","name": "A Google Workspace service was configured as unrestricted","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Domain or Tenant Policy Modification (T1484)" ], "attackers_goals": "Malicious apps can be used to access the organization's Google data.", "deduplication_period": "2 Days", "description": "An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.", "name": "A Google Workspace service was configured as unrestricted", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A Google Workspace user was added to a group modified +1 −1
analytics/a-google-workspace-user-was-added-to-a-groupRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation (T1098)""Account Manipulation (T1098)"],],"attackers_goals": "Adversaries may manipulate accounts and groups to maintain access to victim systems.","attackers_goals": "Adversaries may manipulate accounts and groups to maintain access to victim systems.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A user added another user to a Google Workspace group.","description": "A user added another user to a Google Workspace group.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the user was added to a sensitive group. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the user was added to a sensitive group. Follow further actions done by the account.","name": "A Google Workspace user was added to a group","name": "A Google Workspace user was added to a group","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Account Manipulation (T1098)" ], "attackers_goals": "Adversaries may manipulate accounts and groups to maintain access to victim systems.", "deduplication_period": "5 Days", "description": "A user added another user to a Google Workspace group.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the user was added to a sensitive group. Follow further actions done by the account.", "name": "A Google Workspace user was added to a group", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A Google Workspace user was removed from a group modified +1 −1
analytics/a-google-workspace-user-was-removed-from-a-groupRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Impact (TA0040)""Impact (TA0040)"],],"attack_techniques": ["attack_techniques": ["Account Access Removal (T1531)""Account Access Removal (T1531)"],],"attackers_goals": "Adversaries may interrupt the availability of services and resources by inhibiting access to users.","attackers_goals": "Adversaries may interrupt the availability of services and resources by inhibiting access to users.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A user removed another user from a Google Workspace group.","description": "A user removed another user from a Google Workspace group.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the user's work can be affected by this action. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the user's work can be affected by this action. Follow further actions done by the account.","name": "A Google Workspace user was removed from a group","name": "A Google Workspace user was removed from a group","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Impact (TA0040)" ], "attack_techniques": [ "Account Access Removal (T1531)" ], "attackers_goals": "Adversaries may interrupt the availability of services and resources by inhibiting access to users.", "deduplication_period": "5 Days", "description": "A user removed another user from a Google Workspace group.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the user's work can be affected by this action. Follow further actions done by the account.", "name": "A Google Workspace user was removed from a group", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A mail forwarding rule was configured in Google Workspace modified +1 −1
analytics/a-mail-forwarding-rule-was-configured-in-google-workspaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Email Collection: Email Forwarding Rule (T1114.003)","Email Collection: Email Forwarding Rule (T1114.003)","Automated Exfiltration (T1020)","Automated Exfiltration (T1020)","Email Collection (T1114)""Email Collection (T1114)"],],"attackers_goals": "Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal information, and further gain intelligence on the victim or the victim's organization to use as part of further exploits or operations. Furthermore, email forwarding rules can allow adversaries to maintain persistent access to victim's emails even after compromised credentials are reset by administrators.","attackers_goals": "Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal information, and further gain intelligence on the victim or the victim's organization to use as part of further exploits or operations. Furthermore, email forwarding rules can allow adversaries to maintain persistent access to victim's emails even after compromised credentials are reset by administrators.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "A rule was set up to forward emails outside the Google Workspace domain.","description": "A rule was set up to forward emails outside the Google Workspace domain.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to preform this action, * and look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to preform this action, * and look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Follow further actions done by the account.","name": "A mail forwarding rule was configured in Google Workspace","name": "A mail forwarding rule was configured in Google Workspace","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Medium","severity": "Medium","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Email Collection: Email Forwarding Rule (T1114.003)", "Automated Exfiltration (T1020)", "Email Collection (T1114)" ], "attackers_goals": "Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal information, and further gain intelligence on the victim or the victim's organization to use as part of further exploits or operations. Furthermore, email forwarding rules can allow adversaries to maintain persistent access to victim's emails even after compromised credentials are reset by administrators.", "deduplication_period": "2 Days", "description": "A rule was set up to forward emails outside the Google Workspace domain.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to preform this action, * and look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Follow further actions done by the account.", "name": "A mail forwarding rule was configured in Google Workspace", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Medium", "test_period": "N/A (single event)", -
▸ ▾ A Microsoft Teams application was installed modified +1 −1
analytics/a-microsoft-teams-application-was-installedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Cloud Application Integration (T1671)""Cloud Application Integration (T1671)"],],"attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.","attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A Microsoft Teams application was installed.","description": "A Microsoft Teams application was installed.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the application was created by a certified and trusted entity. Evaluate the permissions requested by the application to determine if they are excessive or unusual. Determine if it is within the user's role to install this type of application. Correlate the alert with the sign-in event to get additional information on the identity performing the action. Follow further actions done by the account.","investigative_actions": "Confirm that the application was created by a certified and trusted entity. Evaluate the permissions requested by the application to determine if they are excessive or unusual. Determine if it is within the user's role to install this type of application. Correlate the alert with the sign-in event to get additional information on the identity performing the action. Follow further actions done by the account.","name": "A Microsoft Teams application was installed","name": "A Microsoft Teams application was installed","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Cloud Application Integration (T1671)" ], "attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.", "deduplication_period": "1 Day", "description": "A Microsoft Teams application was installed.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the application was created by a certified and trusted entity. Evaluate the permissions requested by the application to determine if they are excessive or unusual. Determine if it is within the user's role to install this type of application. Correlate the alert with the sign-in event to get additional information on the identity performing the action. Follow further actions done by the account.", "name": "A Microsoft Teams application was installed", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A Microsoft Teams bot was added to a team modified +1 −1
analytics/a-microsoft-teams-bot-was-added-to-a-teamRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Cloud Application Integration (T1671)""Cloud Application Integration (T1671)"],],"attackers_goals": "Attackers may leverage Teams bots to maintain persistent access to compromised Teams accounts.","attackers_goals": "Attackers may leverage Teams bots to maintain persistent access to compromised Teams accounts.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user added a bot to a team in Microsoft Teams.","description": "A user added a bot to a team in Microsoft Teams.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the bot was created by a certified and trusted entity. Evaluate the permissions requested by the bot to determine if they are excessive or unusual. Determine if it is within the user's role to add bots to teams. Follow further actions done by the account.","investigative_actions": "Confirm that the bot was created by a certified and trusted entity. Evaluate the permissions requested by the bot to determine if they are excessive or unusual. Determine if it is within the user's role to add bots to teams. Follow further actions done by the account.","name": "A Microsoft Teams bot was added to a team","name": "A Microsoft Teams bot was added to a team","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Cloud Application Integration (T1671)" ], "attackers_goals": "Attackers may leverage Teams bots to maintain persistent access to compromised Teams accounts.", "deduplication_period": "1 Day", "description": "A user added a bot to a team in Microsoft Teams.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the bot was created by a certified and trusted entity. Evaluate the permissions requested by the bot to determine if they are excessive or unusual. Determine if it is within the user's role to add bots to teams. Follow further actions done by the account.", "name": "A Microsoft Teams bot was added to a team", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A third-party application's access to the Google Workspace domain's resources was revoked modified +1 −1
analytics/a-third-party-application-s-access-to-the-google-workspace-domain-s-resources-was-revokedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Impact (TA0040)""Impact (TA0040)"],],"attack_techniques": ["attack_techniques": ["Account Access Removal (T1531)""Account Access Removal (T1531)"],],"attackers_goals": "An attacker might remove an application to impair the environment.","attackers_goals": "An attacker might remove an application to impair the environment.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An identity removed a third-party application's access to Google Workspace domain's resources.","description": "An identity removed a third-party application's access to Google Workspace domain's resources.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check the Google Workspace Application settings to determine which actions were triggered. Investigate the source of the request and the user associated with it. Review the access control policies to determine if the removal of the application is allowed.","investigative_actions": "Check the Google Workspace Application settings to determine which actions were triggered. Investigate the source of the request and the user associated with it. Review the access control policies to determine if the removal of the application is allowed.","name": "A third-party application's access to the Google Workspace domain's resources was revoked","name": "A third-party application's access to the Google Workspace domain's resources was revoked","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Impact (TA0040)" ], "attack_techniques": [ "Account Access Removal (T1531)" ], "attackers_goals": "An attacker might remove an application to impair the environment.", "deduplication_period": "5 Days", "description": "An identity removed a third-party application's access to Google Workspace domain's resources.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check the Google Workspace Application settings to determine which actions were triggered. Investigate the source of the request and the user associated with it. Review the access control policies to determine if the removal of the application is allowed.", "name": "A third-party application's access to the Google Workspace domain's resources was revoked", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A third-party application was authorized to access the Google Workspace APIs modified +1 −1
analytics/a-third-party-application-was-authorized-to-access-the-google-workspace-apisRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Gain access to Google Workspace data and services. Collect confidential information from Google Workspace. Compromise user accounts and data.","attackers_goals": "Gain access to Google Workspace data and services. Collect confidential information from Google Workspace. Compromise user accounts and data.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call.","description": "A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check which account was granted access to the Domain API. Identify the source IP address of the request. Verify the legitimacy of the request.","investigative_actions": "Check which account was granted access to the Domain API. Identify the source IP address of the request. Verify the legitimacy of the request.","name": "A third-party application was authorized to access the Google Workspace APIs","name": "A third-party application was authorized to access the Google Workspace APIs","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "Gain access to Google Workspace data and services. Collect confidential information from Google Workspace. Compromise user accounts and data.", "deduplication_period": "5 Days", "description": "A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check which account was granted access to the Domain API. Identify the source IP address of the request. Verify the legitimacy of the request.", "name": "A third-party application was authorized to access the Google Workspace APIs", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A user accessed multiple time-consuming websites modified +1 −1
analytics/a-user-accessed-multiple-time-consuming-websitesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Reconnaissance (TA0043)""Reconnaissance (TA0043)"],],"attack_techniques": ["attack_techniques": ["Search Open Websites/Domains (T1593)""Search Open Websites/Domains (T1593)"],],"attackers_goals": "A user may utilize work time for personal reasons.","attackers_goals": "A user may utilize work time for personal reasons.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user was observed visiting multiple domains for personal reasons. Time theft happens when an employee is paid to work but did not actually work during that time. It might affect your business as it reduces the employee's efficiency.","description": "A user was observed visiting multiple domains for personal reasons. Time theft happens when an employee is paid to work but did not actually work during that time. It might affect your business as it reduces the employee's efficiency.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Investigate the domains accessed and how popular they are in the organization. Verify that the user is not part of a department that visits these websites as part of their daily operations.","investigative_actions": "Investigate the domains accessed and how popular they are in the organization. Verify that the user is not part of a department that visits these websites as part of their daily operations.","name": "A user accessed multiple time-consuming websites","name": "A user accessed multiple time-consuming websites","required_data": ["required_data": ["Palo Alto Networks Firewall EAL Logs","Palo Alto Networks Firewall EAL Logs","Palo Alto Networks Firewall threat Logs","Palo Alto Networks Firewall threat Logs","Palo Alto Networks Firewall EAL Logs","Palo Alto Networks Firewall EAL Logs","XDR Agent""XDR Agent"Show markdown source
@@ -4,17 +4,17 @@ "Reconnaissance (TA0043)" ], "attack_techniques": [ "Search Open Websites/Domains (T1593)" ], "attackers_goals": "A user may utilize work time for personal reasons.", "deduplication_period": "1 Day", "description": "A user was observed visiting multiple domains for personal reasons. Time theft happens when an employee is paid to work but did not actually work during that time. It might affect your business as it reduces the employee's efficiency.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Investigate the domains accessed and how popular they are in the organization. Verify that the user is not part of a department that visits these websites as part of their daily operations.", "name": "A user accessed multiple time-consuming websites", "required_data": [ "Palo Alto Networks Firewall EAL Logs", "Palo Alto Networks Firewall threat Logs", "Palo Alto Networks Firewall EAL Logs", "XDR Agent" -
▸ ▾ A user accessed multiple unusual resources via SSO modified +1 −1
analytics/a-user-accessed-multiple-unusual-resources-via-ssoRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)","Valid Accounts (T1078)","Cloud Service Dashboard (T1538)","Cloud Service Dashboard (T1538)","Cloud Service Discovery (T1526)""Cloud Service Discovery (T1526)"],],"attackers_goals": "Unusual resources may be accessed for various purposes, including exfiltration, lateral movement, etc.","attackers_goals": "Unusual resources may be accessed for various purposes, including exfiltration, lateral movement, etc.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account.","description": "A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Investigate the resources that were accessed to determine if they were used for legitimate purposes or malicious activity.","investigative_actions": "Investigate the resources that were accessed to determine if they were used for legitimate purposes or malicious activity.","name": "A user accessed multiple unusual resources via SSO","name": "A user accessed multiple unusual resources via SSO","required_data": ["required_data": ["AzureAD","AzureAD","Azure SignIn Log","Azure SignIn Log","Idira","Idira","Duo","Duo",Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Valid Accounts (T1078)", "Cloud Service Dashboard (T1538)", "Cloud Service Discovery (T1526)" ], "attackers_goals": "Unusual resources may be accessed for various purposes, including exfiltration, lateral movement, etc.", "deduplication_period": "1 Day", "description": "A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Investigate the resources that were accessed to determine if they were used for legitimate purposes or malicious activity.", "name": "A user accessed multiple unusual resources via SSO", "required_data": [ "AzureAD", "Azure SignIn Log", "Idira", "Duo", -
▸ ▾ A user accessed Okta's admin application modified +1 −1
analytics/a-user-accessed-okta-s-admin-applicationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@"attack_techniques": ["attack_techniques": ["Account Manipulation (T1098)","Account Manipulation (T1098)","Domain or Tenant Policy Modification (T1484)","Domain or Tenant Policy Modification (T1484)","Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Adversaries are attempting to infiltrate Okta's administrative application, a breach that could lead to the manipulation of authentication procedures, creation of persistent user accounts, and various activities aiding in the compromise of additional assets.","attackers_goals": "Adversaries are attempting to infiltrate Okta's administrative application, a breach that could lead to the manipulation of authentication procedures, creation of persistent user accounts, and various activities aiding in the compromise of additional assets.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An attempt to access Okta's admin management application.","description": "An attempt to access Okta's admin management application.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN).","investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN).","name": "A user accessed Okta's admin application","name": "A user accessed Okta's admin application","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -8,17 +8,17 @@ "attack_techniques": [ "Account Manipulation (T1098)", "Domain or Tenant Policy Modification (T1484)", "Valid Accounts (T1078)" ], "attackers_goals": "Adversaries are attempting to infiltrate Okta's administrative application, a breach that could lead to the manipulation of authentication procedures, creation of persistent user accounts, and various activities aiding in the compromise of additional assets.", "deduplication_period": "1 Day", "description": "An attempt to access Okta's admin management application.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN).", "name": "A user accessed Okta's admin application", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A user attempted to bypass Okta MFA modified +1 −1
analytics/a-user-attempted-to-bypass-okta-mfaRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Modify Authentication Process (T1556)","Modify Authentication Process (T1556)","Multi-Factor Authentication Request Generation (T1621)""Multi-Factor Authentication Request Generation (T1621)"],],"attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user may have attempted to bypass Okta MFA.","description": "A user may have attempted to bypass Okta MFA.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Contact the user who attempted to bypass MFA and ensure the request was legitimate. Check if the user successfully authenticated after the event.","investigative_actions": "Contact the user who attempted to bypass MFA and ensure the request was legitimate. Check if the user successfully authenticated after the event.","name": "A user attempted to bypass Okta MFA","name": "A user attempted to bypass Okta MFA","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Modify Authentication Process (T1556)", "Multi-Factor Authentication Request Generation (T1621)" ], "attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.", "deduplication_period": "1 Day", "description": "A user may have attempted to bypass Okta MFA.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Contact the user who attempted to bypass MFA and ensure the request was legitimate. Check if the user successfully authenticated after the event.", "name": "A user attempted to bypass Okta MFA", "required_data": [ "Okta Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ A user modified an Okta MFA factor modified +1 −1
analytics/a-user-modified-an-okta-mfa-factorRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Modify Authentication Process (T1556)","Modify Authentication Process (T1556)","Modify Authentication Process: Multi-Factor Authentication (T1556.006)""Modify Authentication Process: Multi-Factor Authentication (T1556.006)"],],"attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An Okta MFA factor was modified by a user, suggesting a potential compromise of the account.","description": "An Okta MFA factor was modified by a user, suggesting a potential compromise of the account.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Contact the user and ensure the operation was legitimate. Check if the user modifies more factors. If the user activates a weak factor, check for abnormal successful sign-ins from different countries and times. If the user deactivates a strong factor, check if he authenticates with unusual factors and checks for abnormal successful sign-ins from different countries and times.","investigative_actions": "Contact the user and ensure the operation was legitimate. Check if the user modifies more factors. If the user activates a weak factor, check for abnormal successful sign-ins from different countries and times. If the user deactivates a strong factor, check if he authenticates with unusual factors and checks for abnormal successful sign-ins from different countries and times.","name": "A user modified an Okta MFA factor","name": "A user modified an Okta MFA factor","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Modify Authentication Process (T1556)", "Modify Authentication Process: Multi-Factor Authentication (T1556.006)" ], "attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.", "deduplication_period": "1 Day", "description": "An Okta MFA factor was modified by a user, suggesting a potential compromise of the account.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Contact the user and ensure the operation was legitimate. Check if the user modifies more factors. If the user activates a weak factor, check for abnormal successful sign-ins from different countries and times. If the user deactivates a strong factor, check if he authenticates with unusual factors and checks for abnormal successful sign-ins from different countries and times.", "name": "A user modified an Okta MFA factor", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A user modified an Okta network zone modified +1 −1
analytics/a-user-modified-an-okta-network-zoneRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)""Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)"],],"attackers_goals": "An attacker may attempt to modify an Okta network zone to weaken an organization's security controls.","attackers_goals": "An attacker may attempt to modify an Okta network zone to weaken an organization's security controls.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "An Okta network zone was modified by a user.","description": "An Okta network zone was modified by a user.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other network zones have been changed or removed.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other network zones have been changed or removed.","name": "A user modified an Okta network zone","name": "A user modified an Okta network zone","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)" ], "attackers_goals": "An attacker may attempt to modify an Okta network zone to weaken an organization's security controls.", "deduplication_period": "2 Days", "description": "An Okta network zone was modified by a user.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other network zones have been changed or removed.", "name": "A user modified an Okta network zone", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A user modified an Okta policy rule modified +1 −1
analytics/a-user-modified-an-okta-policy-ruleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Domain or Tenant Policy Modification (T1484)","Domain or Tenant Policy Modification (T1484)","Modify Authentication Process (T1556)""Modify Authentication Process (T1556)"],],"attackers_goals": "An attacker may attempt to modify an Okta policy rule to weaken an organization's security controls.","attackers_goals": "An attacker may attempt to modify an Okta policy rule to weaken an organization's security controls.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "An Okta policy rule was modified by a user, suggesting a potential compromise of the account.","description": "An Okta policy rule was modified by a user, suggesting a potential compromise of the account.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other security policies have been changed or removed.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other security policies have been changed or removed.","name": "A user modified an Okta policy rule","name": "A user modified an Okta policy rule","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Domain or Tenant Policy Modification (T1484)", "Modify Authentication Process (T1556)" ], "attackers_goals": "An attacker may attempt to modify an Okta policy rule to weaken an organization's security controls.", "deduplication_period": "2 Days", "description": "An Okta policy rule was modified by a user, suggesting a potential compromise of the account.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other security policies have been changed or removed.", "name": "A user modified an Okta policy rule", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ A user observed and reported unusual activity in Okta modified +1 −1
analytics/a-user-observed-and-reported-unusual-activity-in-oktaRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.","attackers_goals": "An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user observed and reported unusual activity in Okta.","description": "A user observed and reported unusual activity in Okta.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Investigate the original event that was reported as suspicious. Contact the user and understand why he reported the activity as suspicious. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account.","investigative_actions": "Investigate the original event that was reported as suspicious. Contact the user and understand why he reported the activity as suspicious. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account.","name": "A user observed and reported unusual activity in Okta","name": "A user observed and reported unusual activity in Okta","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.", "deduplication_period": "1 Day", "description": "A user observed and reported unusual activity in Okta.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Investigate the original event that was reported as suspicious. Contact the user and understand why he reported the activity as suspicious. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account.", "name": "A user observed and reported unusual activity in Okta", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ A user uploaded malware to SharePoint or OneDrive modified +1 −1
analytics/a-user-uploaded-malware-to-sharepoint-or-onedriveRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Taint Shared Content (T1080)","Taint Shared Content (T1080)","User Execution: Malicious File (T1204.002)""User Execution: Malicious File (T1204.002)"],],"attackers_goals": "An attacker may upload malware to a shared location to gain execution and move laterally.","attackers_goals": "An attacker may upload malware to a shared location to gain execution and move laterally.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user uploaded a file that was classified as malware to SharePoint or OneDrive.","description": "A user uploaded a file that was classified as malware to SharePoint or OneDrive.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Data Detection & Response","detector_tags": "Data Detection & Response","investigative_actions": "Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check the file that was uploaded for any malicious indicators. Follow further actions done by the account.","investigative_actions": "Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check the file that was uploaded for any malicious indicators. Follow further actions done by the account.","name": "A user uploaded malware to SharePoint or OneDrive","name": "A user uploaded malware to SharePoint or OneDrive","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "3 Hours","test_period": "3 Hours",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Taint Shared Content (T1080)", "User Execution: Malicious File (T1204.002)" ], "attackers_goals": "An attacker may upload malware to a shared location to gain execution and move laterally.", "deduplication_period": "1 Day", "description": "A user uploaded a file that was classified as malware to SharePoint or OneDrive.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Data Detection & Response", "investigative_actions": "Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check the file that was uploaded for any malicious indicators. Follow further actions done by the account.", "name": "A user uploaded malware to SharePoint or OneDrive", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "3 Hours", -
▸ ▾ Admin privileges were granted to a Google Workspace user modified +1 −1
analytics/admin-privileges-were-granted-to-a-google-workspace-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Gain access to sensitive data stored in Google Workspace. Manipulate or delete data stored in Google Workspace. Gain access to privileged features in Google Workspace.","attackers_goals": "Gain access to sensitive data stored in Google Workspace. Manipulate or delete data stored in Google Workspace. Gain access to privileged features in Google Workspace.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "Admin privileges were granted to a Google Workspace user. This user now has access to additional administrative functions and settings.","description": "Admin privileges were granted to a Google Workspace user. This user now has access to additional administrative functions and settings.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check which Google Workspace user was granted the admin privileges. Check if the user is authorized to be granted such privileges. Review the audit logs to determine the actions taken by the user.","investigative_actions": "Check which Google Workspace user was granted the admin privileges. Check if the user is authorized to be granted such privileges. Review the audit logs to determine the actions taken by the user.","name": "Admin privileges were granted to a Google Workspace user","name": "Admin privileges were granted to a Google Workspace user","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "Gain access to sensitive data stored in Google Workspace. Manipulate or delete data stored in Google Workspace. Gain access to privileged features in Google Workspace.", "deduplication_period": "5 Days", "description": "Admin privileges were granted to a Google Workspace user. This user now has access to additional administrative functions and settings.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check which Google Workspace user was granted the admin privileges. Check if the user is authorized to be granted such privileges. Review the audit logs to determine the actions taken by the user.", "name": "Admin privileges were granted to a Google Workspace user", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ An app was added to Google Marketplace modified +1 −1
analytics/an-app-was-added-to-google-marketplaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Command and Control (TA0011)""Command and Control (TA0011)"],],"attack_techniques": ["attack_techniques": ["Remote Access Tools (T1219)""Remote Access Tools (T1219)"],],"attackers_goals": "An adversary may add a malicious application to an organization's Google Workspace domain to maintain a presence in their target's organization and steal data.","attackers_goals": "An adversary may add a malicious application to an organization's Google Workspace domain to maintain a presence in their target's organization and steal data.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An app was added to the Google Workspace Marketplace.","description": "An app was added to the Google Workspace Marketplace.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate the new app that was added to Google workspace Marketplace. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate the new app that was added to Google workspace Marketplace. Follow further actions done by the account.","name": "An app was added to Google Marketplace","name": "An app was added to Google Marketplace","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Command and Control (TA0011)" ], "attack_techniques": [ "Remote Access Tools (T1219)" ], "attackers_goals": "An adversary may add a malicious application to an organization's Google Workspace domain to maintain a presence in their target's organization and steal data.", "deduplication_period": "5 Days", "description": "An app was added to the Google Workspace Marketplace.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate the new app that was added to Google workspace Marketplace. Follow further actions done by the account.", "name": "An app was added to Google Marketplace", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ An app was added to the Google Workspace trusted OAuth apps list modified +1 −1
analytics/an-app-was-added-to-the-google-workspace-trusted-oauth-apps-listRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Modify Authentication Process (T1556)""Modify Authentication Process (T1556)"],],"attackers_goals": "Malicious OAuth apps can be used to request elevated permissions or to impersonate another user.","attackers_goals": "Malicious OAuth apps can be used to request elevated permissions or to impersonate another user.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "An identity added an OAuth app to the Google Workspace trusted OAuth apps list.","description": "An identity added an OAuth app to the Google Workspace trusted OAuth apps list.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was added to the trusted apps list looks suspicious. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was added to the trusted apps list looks suspicious. Follow further actions done by the account.","name": "An app was added to the Google Workspace trusted OAuth apps list","name": "An app was added to the Google Workspace trusted OAuth apps list","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Modify Authentication Process (T1556)" ], "attackers_goals": "Malicious OAuth apps can be used to request elevated permissions or to impersonate another user.", "deduplication_period": "2 Days", "description": "An identity added an OAuth app to the Google Workspace trusted OAuth apps list.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was added to the trusted apps list looks suspicious. Follow further actions done by the account.", "name": "An app was added to the Google Workspace trusted OAuth apps list", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ An app was removed from a blocked list in Google Workspace modified +1 −1
analytics/an-app-was-removed-from-a-blocked-list-in-google-workspaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Modify Authentication Process (T1556)""Modify Authentication Process (T1556)"],],"attackers_goals": "Malicious OAuth Apps can be used to request elevated permissions or to impersonate another user.","attackers_goals": "Malicious OAuth Apps can be used to request elevated permissions or to impersonate another user.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "An identity removed an app from Google Workspace blocked OAuth or third-party apps list.","description": "An identity removed an app from Google Workspace blocked OAuth or third-party apps list.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was removed from the trusted apps list looks suspicious. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was removed from the trusted apps list looks suspicious. Follow further actions done by the account.","name": "An app was removed from a blocked list in Google Workspace","name": "An app was removed from a blocked list in Google Workspace","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Modify Authentication Process (T1556)" ], "attackers_goals": "Malicious OAuth Apps can be used to request elevated permissions or to impersonate another user.", "deduplication_period": "2 Days", "description": "An identity removed an app from Google Workspace blocked OAuth or third-party apps list.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was removed from the trusted apps list looks suspicious. Follow further actions done by the account.", "name": "An app was removed from a blocked list in Google Workspace", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ An AWS GuardDuty IP set was created modified +1 −1
analytics/an-aws-guardduty-ip-set-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)""Impair Defenses (T1562)"],],"attackers_goals": "Evade detection.","attackers_goals": "Evade detection.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An AWS GuardDuty IP set has been created.","description": "An AWS GuardDuty IP set has been created.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Check which IP set has been modified and confirm the changes.","investigative_actions": "Check which IP set has been modified and confirm the changes.","name": "An AWS GuardDuty IP set was created","name": "An AWS GuardDuty IP set was created","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)" ], "attackers_goals": "Evade detection.", "deduplication_period": "5 Days", "description": "An AWS GuardDuty IP set has been created.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Check which IP set has been modified and confirm the changes.", "name": "An AWS GuardDuty IP set was created", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ An Azure Suppression Rule was created modified +1 −1
analytics/an-azure-suppression-rule-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)""Impair Defenses (T1562)"],],"attackers_goals": "Bypass security measures.","attackers_goals": "Bypass security measures.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An Azure Suppression Rule was created.","description": "An Azure Suppression Rule was created.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Investigate the user's activity to determine the cause of the alert.","investigative_actions": "Investigate the user's activity to determine the cause of the alert.","name": "An Azure Suppression Rule was created","name": "An Azure Suppression Rule was created","required_data": ["required_data": ["Azure Audit Log""Azure Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)" ], "attackers_goals": "Bypass security measures.", "deduplication_period": "5 Days", "description": "An Azure Suppression Rule was created.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Investigate the user's activity to determine the cause of the alert.", "name": "An Azure Suppression Rule was created", "required_data": [ "Azure Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ An identity disabled bucket logging modified +1 −1
analytics/an-identity-disabled-bucket-loggingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Avoid detection by disabling cloud logging capabilities.","attackers_goals": "Avoid detection by disabling cloud logging capabilities.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An identity disabled bucket logging.","description": "An identity disabled bucket logging.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "Data Detection & Response","detector_tags": "Data Detection & Response, Cloud Log Tampering Analytics","investigative_actions": "Determine whether this activity was done on purpose. Examine additional API calls made by the identity.","investigative_actions": "Determine whether this activity was done on purpose. Examine additional API calls made by the identity.","name": "An identity disabled bucket logging","name": "An identity disabled bucket logging","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Avoid detection by disabling cloud logging capabilities.", "deduplication_period": "5 Days", "description": "An identity disabled bucket logging.", "detection_modules": "Cloud", - "detector_tags": "Data Detection & Response", + "detector_tags": "Data Detection & Response, Cloud Log Tampering Analytics", "investigative_actions": "Determine whether this activity was done on purpose. Examine additional API calls made by the identity.", "name": "An identity disabled bucket logging", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ An identity started an AWS SSM session modified +1 −1
analytics/an-identity-started-an-aws-ssm-sessionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Remote Services: Direct Cloud VM Connections (T1021.008)","Remote Services: Direct Cloud VM Connections (T1021.008)","Remote Services: Cloud Services (T1021.007)""Remote Services: Cloud Services (T1021.007)"],],"attackers_goals": "Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.","attackers_goals": "Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.","deduplication_period": "3 Days","deduplication_period": "3 Days","description": "An identity started an AWS SSM interactive session.","description": "An identity started an AWS SSM interactive session.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "Cloud Lateral Movement Analytics","detector_tags": "Cloud Lateral Movement Analytics, SSM Remote Management Analytics","investigative_actions": "Examine the specifics of the SSM session, including the source IP address, identity, and timestamp. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant instance.","investigative_actions": "Examine the specifics of the SSM session, including the source IP address, identity, and timestamp. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant instance.","name": "An identity started an AWS SSM session","name": "An identity started an AWS SSM session","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Remote Services: Direct Cloud VM Connections (T1021.008)", "Remote Services: Cloud Services (T1021.007)" ], "attackers_goals": "Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.", "deduplication_period": "3 Days", "description": "An identity started an AWS SSM interactive session.", "detection_modules": "Cloud", - "detector_tags": "Cloud Lateral Movement Analytics", + "detector_tags": "Cloud Lateral Movement Analytics, SSM Remote Management Analytics", "investigative_actions": "Examine the specifics of the SSM session, including the source IP address, identity, and timestamp. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant instance.", "name": "An identity started an AWS SSM session", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ An inactive user attempted to authenticate added +60 −0 New Identity Analytics detector for a user with no activity against the target in 30 days authenticating, raised to Low when the source IP is risky.
analytics/an-inactive-user-attempted-to-authenticateRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -0,0 +1,60 @@{"activation_period": "14 Days","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts: Cloud Accounts (T1078.004)"],"attackers_goals": "Use an account that was possibly compromised in the past to gain access to the network.","deduplication_period": "1 Day","description": "A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.","detection_modules": "Identity Analytics","detector_tags": "","investigative_actions": "Confirm that the activity is benign (e.g. the user returned from a long leave of absence).","name": "An inactive user attempted to authenticate","required_data": [],"severity": "Informational","test_period": "N/A (single event)","variations": [{"name": "Successful authentication by an inactive user from a risky IP address","severity": "Low","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts: Cloud Accounts (T1078.004)"],"description": "A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.","attackers_goals": "Use an account that was possibly compromised in the past to gain access to the network.","investigative_actions": "Confirm that the activity is benign (e.g. the user returned from a long leave of absence)."},{"name": "An inactive user attempted to authenticate from a risky IP address","severity": "Low","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts: Cloud Accounts (T1078.004)"],"description": "A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.","attackers_goals": "Use an account that was possibly compromised in the past to gain access to the network.","investigative_actions": "Confirm that the activity is benign (e.g. the user returned from a long leave of absence)."},{"name": "Successful authentication by an inactive user","severity": "Informational","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts: Cloud Accounts (T1078.004)"],"description": "A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.","attackers_goals": "Use an account that was possibly compromised in the past to gain access to the network.","investigative_actions": "Confirm that the activity is benign (e.g. the user returned from a long leave of absence)."}]}Show markdown source
@@ -0,0 +1,60 @@ +{ + "activation_period": "14 Days", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts: Cloud Accounts (T1078.004)" + ], + "attackers_goals": "Use an account that was possibly compromised in the past to gain access to the network.", + "deduplication_period": "1 Day", + "description": "A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.", + "detection_modules": "Identity Analytics", + "detector_tags": "", + "investigative_actions": "Confirm that the activity is benign (e.g. the user returned from a long leave of absence).", + "name": "An inactive user attempted to authenticate", + "required_data": [], + "severity": "Informational", + "test_period": "N/A (single event)", + "variations": [ + { + "name": "Successful authentication by an inactive user from a risky IP address", + "severity": "Low", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts: Cloud Accounts (T1078.004)" + ], + "description": "A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.", + "attackers_goals": "Use an account that was possibly compromised in the past to gain access to the network.", + "investigative_actions": "Confirm that the activity is benign (e.g. the user returned from a long leave of absence)." + }, + { + "name": "An inactive user attempted to authenticate from a risky IP address", + "severity": "Low", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts: Cloud Accounts (T1078.004)" + ], + "description": "A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.", + "attackers_goals": "Use an account that was possibly compromised in the past to gain access to the network.", + "investigative_actions": "Confirm that the activity is benign (e.g. the user returned from a long leave of absence)." + }, + { + "name": "Successful authentication by an inactive user", + "severity": "Informational", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts: Cloud Accounts (T1078.004)" + ], + "description": "A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication.", + "attackers_goals": "Use an account that was possibly compromised in the past to gain access to the network.", + "investigative_actions": "Confirm that the activity is benign (e.g. the user returned from a long leave of absence)." + } + ] +} -
▸ ▾ An operation was performed by an identity from a domain that was not seen in the organization modified +1 −1
analytics/an-operation-was-performed-by-an-identity-from-a-domain-that-was-not-seen-in-the-organizationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["External Remote Services (T1133)""External Remote Services (T1133)"],],"attackers_goals": "Gain their initial foothold within the organization and explore the environment to achieve their target.","attackers_goals": "Gain their initial foothold within the organization and explore the environment to achieve their target.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.","description": "An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Investigate the external domain name. Check The cloud identity activity in the organization.","investigative_actions": "Investigate the external domain name. Check The cloud identity activity in the organization.","name": "An operation was performed by an identity from a domain that was not seen in the organization","name": "An operation was performed by an identity from a domain that was not seen in the organization","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "External Remote Services (T1133)" ], "attackers_goals": "Gain their initial foothold within the organization and explore the environment to achieve their target.", "deduplication_period": "5 Days", "description": "An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Investigate the external domain name. Check The cloud identity activity in the organization.", "name": "An operation was performed by an identity from a domain that was not seen in the organization", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "Informational", -
▸ ▾ Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert renamed +4 −4 Renamed from analytics-enhanced-rare-internal-firewall-vulnerability-threat-alert; the rule, its variation and its description now say NGFW Threat Alert explicitly.
analytics/analytics-enhanced-ngfw-threat-alert-rare-internal-firewall-vulnerability-threat-alertRead it here → This file's diff on GitHub ↗ moved from
analytics/analytics-enhanced-rare-internal-firewall-vulnerability-threat-alert.jsonGenerated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -3,35 +3,35 @@"attack_tactics": ["attack_tactics": ["Reconnaissance (TA0043)""Reconnaissance (TA0043)"],],"attack_techniques": ["attack_techniques": ["Active Scanning: Vulnerability Scanning (T1595.002)""Active Scanning: Vulnerability Scanning (T1595.002)"],],"attackers_goals": "Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.","attackers_goals": "Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An internal host triggered a firewall vulnerability alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.","description": "An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.","detection_modules": "","detection_modules": "","detector_tags": "","detector_tags": "","investigative_actions": "Verify the firewall alert details, including the threat name, CVE, and severity. Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections. Determine if the source host is an internal scanner or a compromised asset. Review recent changes or updates on the target system that might have exposed the vulnerability. Check if the traffic was blocked by the firewall or only detected.","investigative_actions": "Verify the firewall alert details, including the threat name, CVE, and severity. Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections. Determine if the source host is an internal scanner or a compromised asset. Review recent changes or updates on the target system that might have exposed the vulnerability. Check if the traffic was blocked by the firewall or only detected.","name": "Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert","name": "Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert","required_data": ["required_data": ["Palo Alto Networks Firewall threat Logs","Palo Alto Networks Firewall threat Logs","XDR Agent""XDR Agent"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [{{"name": "Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak","name": "Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak","severity": "Informational","severity": "Informational","attack_tactics": ["attack_tactics": ["Reconnaissance (TA0043)""Reconnaissance (TA0043)"],],"attack_techniques": ["attack_techniques": ["Active Scanning: Vulnerability Scanning (T1595.002)""Active Scanning: Vulnerability Scanning (T1595.002)"],],"description": "An internal host triggered a firewall vulnerability alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.","description": "An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.","attackers_goals": "Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.","attackers_goals": "Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.","investigative_actions": "Verify the firewall alert details, including the threat name, CVE, and severity. Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections. Determine if the source host is an internal scanner or a compromised asset. Review recent changes or updates on the target system that might have exposed the vulnerability. Check if the traffic was blocked by the firewall or only detected.""investigative_actions": "Verify the firewall alert details, including the threat name, CVE, and severity. Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections. Determine if the source host is an internal scanner or a compromised asset. Review recent changes or updates on the target system that might have exposed the vulnerability. Check if the traffic was blocked by the firewall or only detected."}}]]}}Show markdown source
@@ -3,35 +3,35 @@ "attack_tactics": [ "Reconnaissance (TA0043)" ], "attack_techniques": [ "Active Scanning: Vulnerability Scanning (T1595.002)" ], "attackers_goals": "Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.", "deduplication_period": "1 Day", - "description": "An internal host triggered a firewall vulnerability alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.", + "description": "An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.", "detection_modules": "", "detector_tags": "", "investigative_actions": "Verify the firewall alert details, including the threat name, CVE, and severity. Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections. Determine if the source host is an internal scanner or a compromised asset. Review recent changes or updates on the target system that might have exposed the vulnerability. Check if the traffic was blocked by the firewall or only detected.", - "name": "Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert", + "name": "Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert", "required_data": [ "Palo Alto Networks Firewall threat Logs", "XDR Agent" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ { - "name": "Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak", + "name": "Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak", "severity": "Informational", "attack_tactics": [ "Reconnaissance (TA0043)" ], "attack_techniques": [ "Active Scanning: Vulnerability Scanning (T1595.002)" ], - "description": "An internal host triggered a firewall vulnerability alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.", + "description": "An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.", "attackers_goals": "Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.", "investigative_actions": "Verify the firewall alert details, including the threat name, CVE, and severity. Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections. Determine if the source host is an internal scanner or a compromised asset. Review recent changes or updates on the target system that might have exposed the vulnerability. Check if the traffic was blocked by the firewall or only detected." } ] } -
▸ ▾ Authentication method added to an Azure account modified +1 −1
analytics/authentication-method-added-to-an-azure-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker can add an authentication method to an account, so they can have later access to the tenant and resources.","attackers_goals": "An attacker can add an authentication method to an account, so they can have later access to the tenant and resources.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity attempted to add an Azure authentication method.","description": "An identity attempted to add an Azure authentication method.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the authentication method is legitimate in the organization. Check whether the identity is permitted to perform such actions. Follow the account for possible suspicious or unusual logins.","investigative_actions": "Check if the authentication method is legitimate in the organization. Check whether the identity is permitted to perform such actions. Follow the account for possible suspicious or unusual logins.","name": "Authentication method added to an Azure account","name": "Authentication method added to an Azure account","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An attacker can add an authentication method to an account, so they can have later access to the tenant and resources.", "deduplication_period": "1 Day", "description": "An identity attempted to add an Azure authentication method.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the authentication method is legitimate in the organization. Check whether the identity is permitted to perform such actions. Follow the account for possible suspicious or unusual logins.", "name": "Authentication method added to an Azure account", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ AWS CloudTrail has been stopped modified +1 −1
analytics/aws-cloudtrail-has-been-stoppedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection by limiting collected data.","attackers_goals": "Evade detection by limiting collected data.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail.","description": "A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Verify whether the identity attempted to stop trail logging. Determine if additional trails continue to log activity.","investigative_actions": "Verify whether the identity attempted to stop trail logging. Determine if additional trails continue to log activity.","name": "AWS CloudTrail has been stopped","name": "AWS CloudTrail has been stopped","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection by limiting collected data.", "deduplication_period": "5 Days", "description": "A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Verify whether the identity attempted to stop trail logging. Determine if additional trails continue to log activity.", "name": "AWS CloudTrail has been stopped", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ AWS CloudTrail modification modified +1 −1
analytics/aws-cloudtrail-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection by limiting collected data.","attackers_goals": "Evade detection by limiting collected data.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An identity updated a CloudTrail trail configuration.","description": "An identity updated a CloudTrail trail configuration.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Review the activity of the identity that modified the trail's configuration. Check which trail is affected by this change. Verify whether a new destination has been set for log archiving.","investigative_actions": "Review the activity of the identity that modified the trail's configuration. Check which trail is affected by this change. Verify whether a new destination has been set for log archiving.","name": "AWS CloudTrail modification","name": "AWS CloudTrail modification","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection by limiting collected data.", "deduplication_period": "5 Days", "description": "An identity updated a CloudTrail trail configuration.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Review the activity of the identity that modified the trail's configuration. Check which trail is affected by this change. Verify whether a new destination has been set for log archiving.", "name": "AWS CloudTrail modification", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ AWS Flow Logs deletion modified +1 −1
analytics/aws-flow-logs-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)""Impair Defenses (T1562)"],],"attackers_goals": "Exfiltrate information.","attackers_goals": "Exfiltrate information.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A cloud identity has deleted one or more Flow Logs records.","description": "A cloud identity has deleted one or more Flow Logs records.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Check if the Identity intended to delete the Flow Logs record/s. Check what VPC is affected by this.","investigative_actions": "Check if the Identity intended to delete the Flow Logs record/s. Check what VPC is affected by this.","name": "AWS Flow Logs deletion","name": "AWS Flow Logs deletion","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)" ], "attackers_goals": "Exfiltrate information.", "deduplication_period": "5 Days", "description": "A cloud identity has deleted one or more Flow Logs records.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Check if the Identity intended to delete the Flow Logs record/s. Check what VPC is affected by this.", "name": "AWS Flow Logs deletion", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ AWS S3 bucket data retention policy change through S3 Lifecycle rule modified +1 −1
analytics/aws-s3-bucket-data-retention-policy-change-through-s3-lifecycle-ruleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection by automatically deleting audit logs.","attackers_goals": "Evade detection by automatically deleting audit logs.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule.","description": "A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Review the new S3 bucket lifecycle policy. Check The cloud identity activity prior/after to the lifecycle policy modification.","investigative_actions": "Review the new S3 bucket lifecycle policy. Check The cloud identity activity prior/after to the lifecycle policy modification.","name": "AWS S3 bucket data retention policy change through S3 Lifecycle rule","name": "AWS S3 bucket data retention policy change through S3 Lifecycle rule","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection by automatically deleting audit logs.", "deduplication_period": "5 Days", "description": "A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Review the new S3 bucket lifecycle policy. Check The cloud identity activity prior/after to the lifecycle policy modification.", "name": "AWS S3 bucket data retention policy change through S3 Lifecycle rule", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ AWS SecurityHub findings were modified modified +1 −1
analytics/aws-securityhub-findings-were-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Indicator Removal (T1070)""Indicator Removal (T1070)"],],"attackers_goals": "Bypass security measures implemented by AWS SecurityHub.","attackers_goals": "Bypass security measures implemented by AWS SecurityHub.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "AWS SecurityHub findings were modified.","description": "AWS SecurityHub findings were modified.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Check the current AWS SecurityHub settings and verify they are configured properly.","investigative_actions": "Check the current AWS SecurityHub settings and verify they are configured properly.","name": "AWS SecurityHub findings were modified","name": "AWS SecurityHub findings were modified","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Indicator Removal (T1070)" ], "attackers_goals": "Bypass security measures implemented by AWS SecurityHub.", "deduplication_period": "5 Days", "description": "AWS SecurityHub findings were modified.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Check the current AWS SecurityHub settings and verify they are configured properly.", "name": "AWS SecurityHub findings were modified", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ AWS SSM parameters discovery modified +1 −1
analytics/aws-ssm-parameters-discoveryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)","Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)","Cloud Service Discovery (T1526)""Cloud Service Discovery (T1526)"],],"attackers_goals": "Exfiltrate sensitive secrets stored in SSM parameter store.","attackers_goals": "Exfiltrate sensitive secrets stored in SSM parameter store.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An attempt was made to list parameters stored in AWS SSM.","description": "An attempt was made to list parameters stored in AWS SSM.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "SSM Remote Management Analytics","investigative_actions": "Check if the secrets manager activity aligns with known workflows or automation, or if it indicates abnormal activity. Follow further actions done by the identity.","investigative_actions": "Check if the secrets manager activity aligns with known workflows or automation, or if it indicates abnormal activity. Follow further actions done by the identity.","name": "AWS SSM parameters discovery","name": "AWS SSM parameters discovery","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)", "Cloud Service Discovery (T1526)" ], "attackers_goals": "Exfiltrate sensitive secrets stored in SSM parameter store.", "deduplication_period": "5 Days", "description": "An attempt was made to list parameters stored in AWS SSM.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "SSM Remote Management Analytics", "investigative_actions": "Check if the secrets manager activity aligns with known workflows or automation, or if it indicates abnormal activity. Follow further actions done by the identity.", "name": "AWS SSM parameters discovery", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ AWS SSM parameters retrieval modified +2 −15 Dropped the "Unusual AWS SSM parameters retrieval" variation, cut deduplication from 5 Days to 1 Day, and picked up the SSM Remote Management Analytics tag.
analytics/aws-ssm-parameters-retrievalRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -2,20 +2,20 @@"activation_period": "14 Days","activation_period": "14 Days","attack_tactics": ["attack_tactics": ["Credential Access (TA0006)""Credential Access (TA0006)"],],"attack_techniques": ["attack_techniques": ["Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)""Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)"],],"attackers_goals": "Exfiltrate sensitive secrets stored in AWS SSM parameter store.","attackers_goals": "Exfiltrate sensitive secrets stored in AWS SSM parameter store.","deduplication_period": "5 Days","deduplication_period": "1 Day","description": "An attempt was made to retrieve parameters stored in AWS SSM.","description": "An attempt was made to retrieve parameters stored in AWS SSM.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "SSM Remote Management Analytics","investigative_actions": "Investigate the purpose of the encrypted parameter and assess the sensitivity of its contents. Check if the access aligns with known workflows or automation, or if it indicates abnormal activity.","investigative_actions": "Investigate the purpose of the encrypted parameter and assess the sensitivity of its contents. Check if the access aligns with known workflows or automation, or if it indicates abnormal activity.","name": "AWS SSM parameters retrieval","name": "AWS SSM parameters retrieval","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [@@ -26,24 +26,11 @@"Credential Access (TA0006)""Credential Access (TA0006)"],],"attack_techniques": ["attack_techniques": ["Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)""Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)"],],"description": "An attempt was made to retrieve encrypted parameters stored in AWS SSM.","description": "An attempt was made to retrieve encrypted parameters stored in AWS SSM.","attackers_goals": "Exfiltrate sensitive secrets stored in AWS SSM parameter store.","attackers_goals": "Exfiltrate sensitive secrets stored in AWS SSM parameter store.","investigative_actions": "Investigate the purpose of the encrypted parameter and assess the sensitivity of its contents. Check if the access aligns with known workflows or automation, or if it indicates abnormal activity.""investigative_actions": "Investigate the purpose of the encrypted parameter and assess the sensitivity of its contents. Check if the access aligns with known workflows or automation, or if it indicates abnormal activity."},{"name": "Unusual AWS SSM parameters retrieval","severity": "Informational","attack_tactics": ["Credential Access (TA0006)"],"attack_techniques": ["Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)"],"description": "An attempt was made to retrieve parameters stored in AWS SSM.","attackers_goals": "Exfiltrate sensitive secrets stored in AWS SSM parameter store.","investigative_actions": "Investigate the purpose of the encrypted parameter and assess the sensitivity of its contents. Check if the access aligns with known workflows or automation, or if it indicates abnormal activity."}}]]}}Show markdown source
@@ -2,20 +2,20 @@ "activation_period": "14 Days", "attack_tactics": [ "Credential Access (TA0006)" ], "attack_techniques": [ "Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)" ], "attackers_goals": "Exfiltrate sensitive secrets stored in AWS SSM parameter store.", - "deduplication_period": "5 Days", + "deduplication_period": "1 Day", "description": "An attempt was made to retrieve parameters stored in AWS SSM.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "SSM Remote Management Analytics", "investigative_actions": "Investigate the purpose of the encrypted parameter and assess the sensitivity of its contents. Check if the access aligns with known workflows or automation, or if it indicates abnormal activity.", "name": "AWS SSM parameters retrieval", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ @@ -26,24 +26,11 @@ "Credential Access (TA0006)" ], "attack_techniques": [ "Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)" ], "description": "An attempt was made to retrieve encrypted parameters stored in AWS SSM.", "attackers_goals": "Exfiltrate sensitive secrets stored in AWS SSM parameter store.", "investigative_actions": "Investigate the purpose of the encrypted parameter and assess the sensitivity of its contents. Check if the access aligns with known workflows or automation, or if it indicates abnormal activity." - }, - { - "name": "Unusual AWS SSM parameters retrieval", - "severity": "Informational", - "attack_tactics": [ - "Credential Access (TA0006)" - ], - "attack_techniques": [ - "Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)" - ], - "description": "An attempt was made to retrieve parameters stored in AWS SSM.", - "attackers_goals": "Exfiltrate sensitive secrets stored in AWS SSM parameter store.", - "investigative_actions": "Investigate the purpose of the encrypted parameter and assess the sensitivity of its contents. Check if the access aligns with known workflows or automation, or if it indicates abnormal activity." } ] } -
▸ ▾ AWS SSM send command attempt modified +1 −1
analytics/aws-ssm-send-command-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Remote Services: Direct Cloud VM Connections (T1021.008)","Remote Services: Direct Cloud VM Connections (T1021.008)","Cloud Administration Command (T1651)""Cloud Administration Command (T1651)"],],"attackers_goals": "Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.","attackers_goals": "Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.","deduplication_period": "3 Days","deduplication_period": "3 Days","description": "An identity executed an AWS SSM Document.","description": "An identity executed an AWS SSM Document.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "Cloud Lateral Movement Analytics","detector_tags": "Cloud Lateral Movement Analytics, SSM Remote Management Analytics","investigative_actions": "Examine the code in the SSM document, and the target objects. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant targets.","investigative_actions": "Examine the code in the SSM document, and the target objects. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant targets.","name": "AWS SSM send command attempt","name": "AWS SSM send command attempt","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Remote Services: Direct Cloud VM Connections (T1021.008)", "Cloud Administration Command (T1651)" ], "attackers_goals": "Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.", "deduplication_period": "3 Days", "description": "An identity executed an AWS SSM Document.", "detection_modules": "Cloud", - "detector_tags": "Cloud Lateral Movement Analytics", + "detector_tags": "Cloud Lateral Movement Analytics, SSM Remote Management Analytics", "investigative_actions": "Examine the code in the SSM document, and the target objects. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant targets.", "name": "AWS SSM send command attempt", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ Azure account creation by a non-standard account modified +1 −1
analytics/azure-account-creation-by-a-non-standard-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Account Manipulation (T1098)","Account Manipulation (T1098)","Create Account (T1136)""Create Account (T1136)"],],"attackers_goals": "Create a backdoor account for later access to Azure AD or Azure resources, or delete evidence of such an account.","attackers_goals": "Create a backdoor account for later access to Azure AD or Azure resources, or delete evidence of such an account.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An Azure AD account creation was performed by a user that doesn't typically create users.","description": "An Azure AD account creation was performed by a user that doesn't typically create users.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions by the initiator. Check for new resource creations by the new user. Check if the new user was added to a privileged role. Follow further actions done by the new user.","investigative_actions": "Follow further actions by the initiator. Check for new resource creations by the new user. Check if the new user was added to a privileged role. Follow further actions done by the new user.","name": "Azure account creation by a non-standard account","name": "Azure account creation by a non-standard account","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Account Manipulation (T1098)", "Create Account (T1136)" ], "attackers_goals": "Create a backdoor account for later access to Azure AD or Azure resources, or delete evidence of such an account.", "deduplication_period": "1 Day", "description": "An Azure AD account creation was performed by a user that doesn't typically create users.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Follow further actions by the initiator. Check for new resource creations by the new user. Check if the new user was added to a privileged role. Follow further actions done by the new user.", "name": "Azure account creation by a non-standard account", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Azure account deletion by a non-standard account modified +1 −1
analytics/azure-account-deletion-by-a-non-standard-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Impact (TA0040)""Impact (TA0040)"],],"attack_techniques": ["attack_techniques": ["Account Access Removal (T1531)""Account Access Removal (T1531)"],],"attackers_goals": "Interrupt availability and access to Azure by deleting access accounts.","attackers_goals": "Interrupt availability and access to Azure by deleting access accounts.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An Azure AD account deletion was performed by a user that doesn't typically delete users.","description": "An Azure AD account deletion was performed by a user that doesn't typically delete users.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions by the initiator. Check what services, groups and applications are affected by the deleted user being removed. Check if the deleted user had a privileged role.","investigative_actions": "Follow further actions by the initiator. Check what services, groups and applications are affected by the deleted user being removed. Check if the deleted user had a privileged role.","name": "Azure account deletion by a non-standard account","name": "Azure account deletion by a non-standard account","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Impact (TA0040)" ], "attack_techniques": [ "Account Access Removal (T1531)" ], "attackers_goals": "Interrupt availability and access to Azure by deleting access accounts.", "deduplication_period": "1 Day", "description": "An Azure AD account deletion was performed by a user that doesn't typically delete users.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Follow further actions by the initiator. Check what services, groups and applications are affected by the deleted user being removed. Check if the deleted user had a privileged role.", "name": "Azure account deletion by a non-standard account", "required_data": [ "AzureAD Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Azure AD account unlock/password reset attempt modified +1 −1
analytics/azure-ad-account-unlock-password-reset-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker may switch a valid account's password for persistence.","attackers_goals": "An attacker may switch a valid account's password for persistence.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An attempt to unlock an Azure AD identity or reset its password has occurred.","description": "An attempt to unlock an Azure AD identity or reset its password has occurred.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the password reset is authorized. Check whether the user who reset the password is permitted to perform such actions. Check if the account is in the password reset group or is acting out of scope. Check whether the user has not completed the password reset and cancelled before successfully passing authentication methods. Follow further actions or suspicious logins from the target account.","investigative_actions": "Check if the password reset is authorized. Check whether the user who reset the password is permitted to perform such actions. Check if the account is in the password reset group or is acting out of scope. Check whether the user has not completed the password reset and cancelled before successfully passing authentication methods. Follow further actions or suspicious logins from the target account.","name": "Azure AD account unlock/password reset attempt","name": "Azure AD account unlock/password reset attempt","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An attacker may switch a valid account's password for persistence.", "deduplication_period": "1 Day", "description": "An attempt to unlock an Azure AD identity or reset its password has occurred.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the password reset is authorized. Check whether the user who reset the password is permitted to perform such actions. Check if the account is in the password reset group or is acting out of scope. Check whether the user has not completed the password reset and cancelled before successfully passing authentication methods. Follow further actions or suspicious logins from the target account.", "name": "Azure AD account unlock/password reset attempt", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Azure AD PIM alert disabled modified +1 −1
analytics/azure-ad-pim-alert-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Domain or Tenant Policy Modification (T1484)""Domain or Tenant Policy Modification (T1484)"],],"attackers_goals": "An attacker might want to disable alerts associated with authentication requirements for privileged access. This may allow malicious activities to go unnoticed.","attackers_goals": "An attacker might want to disable alerts associated with authentication requirements for privileged access. This may allow malicious activities to go unnoticed.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity disabled an Azure AD PIM alert.","description": "An identity disabled an Azure AD PIM alert.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check what alert was disabled. Check whether the user that disabled the alert is permitted to perform such actions.","investigative_actions": "Check what alert was disabled. Check whether the user that disabled the alert is permitted to perform such actions.","name": "Azure AD PIM alert disabled","name": "Azure AD PIM alert disabled","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Medium","severity": "Medium","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Domain or Tenant Policy Modification (T1484)" ], "attackers_goals": "An attacker might want to disable alerts associated with authentication requirements for privileged access. This may allow malicious activities to go unnoticed.", "deduplication_period": "1 Day", "description": "An identity disabled an Azure AD PIM alert.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check what alert was disabled. Check whether the user that disabled the alert is permitted to perform such actions.", "name": "Azure AD PIM alert disabled", "required_data": [ "AzureAD Audit Log" ], "severity": "Medium", "test_period": "N/A (single event)", -
▸ ▾ Azure AD PIM elevation request modified +1 −1
analytics/azure-ad-pim-elevation-requestRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Getting elevated permissions to perform malicious actions.","attackers_goals": "Getting elevated permissions to perform malicious actions.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An Azure AD PIM elevation request was denied/approved.","description": "An Azure AD PIM elevation request was denied/approved.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the elevation is authorized. Follow further actions or suspicious logins from the elevated account.","investigative_actions": "Check if the elevation is authorized. Follow further actions or suspicious logins from the elevated account.","name": "Azure AD PIM elevation request","name": "Azure AD PIM elevation request","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "Getting elevated permissions to perform malicious actions.", "deduplication_period": "1 Day", "description": "An Azure AD PIM elevation request was denied/approved.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the elevation is authorized. Follow further actions or suspicious logins from the elevated account.", "name": "Azure AD PIM elevation request", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Azure AD PIM role settings change modified +1 −1
analytics/azure-ad-pim-role-settings-changeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Abuse Elevation Control Mechanism (T1548)","Abuse Elevation Control Mechanism (T1548)","Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker can modify the PIM role settings to make it easier to acquire a privileged account.","attackers_goals": "An attacker can modify the PIM role settings to make it easier to acquire a privileged account.","deduplication_period": "1 Hour","deduplication_period": "1 Hour","description": "An identity changed the PIM role settings.","description": "An identity changed the PIM role settings.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check what role settings have been updated. Check whether the user changing the settings is permitted to perform such actions.","investigative_actions": "Check what role settings have been updated. Check whether the user changing the settings is permitted to perform such actions.","name": "Azure AD PIM role settings change","name": "Azure AD PIM role settings change","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Abuse Elevation Control Mechanism (T1548)", "Valid Accounts (T1078)" ], "attackers_goals": "An attacker can modify the PIM role settings to make it easier to acquire a privileged account.", "deduplication_period": "1 Hour", "description": "An identity changed the PIM role settings.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check what role settings have been updated. Check whether the user changing the settings is permitted to perform such actions.", "name": "Azure AD PIM role settings change", "required_data": [ "AzureAD Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Azure application consent modified +1 −1
analytics/azure-application-consentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@"Phishing (T1566)","Phishing (T1566)","Phishing: Spearphishing Link (T1566.002)","Phishing: Spearphishing Link (T1566.002)","Steal Application Access Token (T1528)","Steal Application Access Token (T1528)","Trusted Relationship (T1199)""Trusted Relationship (T1199)"],],"attackers_goals": "Get access to credentials, data or an organization via applications with sufficient permissions.","attackers_goals": "Get access to credentials, data or an organization via applications with sufficient permissions.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity consented permissions to an application.","description": "An identity consented permissions to an application.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions by the consenting user. Check for new resource creations by the new user. Check how the consenting user got to the application. Verify the application creators. Check what permissions the application requested. Check for possible phishing in the organization.","investigative_actions": "Follow further actions by the consenting user. Check for new resource creations by the new user. Check how the consenting user got to the application. Verify the application creators. Check what permissions the application requested. Check for possible phishing in the organization.","name": "Azure application consent","name": "Azure application consent","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -8,17 +8,17 @@ "Phishing (T1566)", "Phishing: Spearphishing Link (T1566.002)", "Steal Application Access Token (T1528)", "Trusted Relationship (T1199)" ], "attackers_goals": "Get access to credentials, data or an organization via applications with sufficient permissions.", "deduplication_period": "1 Day", "description": "An identity consented permissions to an application.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Follow further actions by the consenting user. Check for new resource creations by the new user. Check how the consenting user got to the application. Verify the application creators. Check what permissions the application requested. Check for possible phishing in the organization.", "name": "Azure application consent", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Azure application credentials added modified +1 −1
analytics/azure-application-credentials-addedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Account Manipulation (T1098)","Account Manipulation (T1098)","Use Alternate Authentication Material (T1550)""Use Alternate Authentication Material (T1550)"],],"attackers_goals": "An attacker may add certificates or modify authentication methods of an application to authenticate as the application.","attackers_goals": "An attacker may add certificates or modify authentication methods of an application to authenticate as the application.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity added credentials to an Azure application.","description": "An identity added credentials to an Azure application.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the modified application is new to the organization. Check whether the account that modified the credentials is supposed to perform such actions. Check for possible logins from the application modified. Follow further actions done by the application.","investigative_actions": "Check if the modified application is new to the organization. Check whether the account that modified the credentials is supposed to perform such actions. Check for possible logins from the application modified. Follow further actions done by the application.","name": "Azure application credentials added","name": "Azure application credentials added","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Account Manipulation (T1098)", "Use Alternate Authentication Material (T1550)" ], "attackers_goals": "An attacker may add certificates or modify authentication methods of an application to authenticate as the application.", "deduplication_period": "1 Day", "description": "An identity added credentials to an Azure application.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the modified application is new to the organization. Check whether the account that modified the credentials is supposed to perform such actions. Check for possible logins from the application modified. Follow further actions done by the application.", "name": "Azure application credentials added", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Azure application URI modification modified +1 −1
analytics/azure-application-uri-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Account Manipulation (T1098)","Account Manipulation (T1098)","Use Alternate Authentication Material (T1550)""Use Alternate Authentication Material (T1550)"],],"attackers_goals": "An attacker may add certificates or modify authentication methods of an application to authenticate as the application.","attackers_goals": "An attacker may add certificates or modify authentication methods of an application to authenticate as the application.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity added or updated an Azure application's URI.","description": "An identity added or updated an Azure application's URI.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check whether the account that modified the URI is supposed to perform such actions. Check for possible logins from the application modified. Check for possible account consents or credential changes regarding the application. Follow further actions done by the application.","investigative_actions": "Check whether the account that modified the URI is supposed to perform such actions. Check for possible logins from the application modified. Check for possible account consents or credential changes regarding the application. Follow further actions done by the application.","name": "Azure application URI modification","name": "Azure application URI modification","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Account Manipulation (T1098)", "Use Alternate Authentication Material (T1550)" ], "attackers_goals": "An attacker may add certificates or modify authentication methods of an application to authenticate as the application.", "deduplication_period": "1 Day", "description": "An identity added or updated an Azure application's URI.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check whether the account that modified the URI is supposed to perform such actions. Check for possible logins from the application modified. Check for possible account consents or credential changes regarding the application. Follow further actions done by the application.", "name": "Azure application URI modification", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Azure diagnostic configuration deletion modified +1 −1
analytics/azure-diagnostic-configuration-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection.","attackers_goals": "Evade detection.","deduplication_period": "3 Hours","deduplication_period": "3 Hours","description": "An attacker might delete the Azure diagnostic settings to evade detection.","description": "An attacker might delete the Azure diagnostic settings to evade detection.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Check the identity and its actions after the deletion action.","investigative_actions": "Check the identity and its actions after the deletion action.","name": "Azure diagnostic configuration deletion","name": "Azure diagnostic configuration deletion","required_data": ["required_data": ["Azure Audit Log""Azure Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection.", "deduplication_period": "3 Hours", "description": "An attacker might delete the Azure diagnostic settings to evade detection.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Check the identity and its actions after the deletion action.", "name": "Azure diagnostic configuration deletion", "required_data": [ "Azure Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ Azure domain federation settings modification attempt modified +1 −1
analytics/azure-domain-federation-settings-modification-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Account Manipulation: Additional Cloud Credentials (T1098.001)","Account Manipulation: Additional Cloud Credentials (T1098.001)","Domain or Tenant Policy Modification (T1484)""Domain or Tenant Policy Modification (T1484)"],],"attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion.","attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user or application attempted to modify the federation settings of the domain.","description": "A user or application attempted to modify the federation settings of the domain.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check what configuration has been changed. Check whether the user changing the configuration is permitted.","investigative_actions": "Check what configuration has been changed. Check whether the user changing the configuration is permitted.","name": "Azure domain federation settings modification attempt","name": "Azure domain federation settings modification attempt","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Account Manipulation: Additional Cloud Credentials (T1098.001)", "Domain or Tenant Policy Modification (T1484)" ], "attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion.", "deduplication_period": "1 Day", "description": "A user or application attempted to modify the federation settings of the domain.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check what configuration has been changed. Check whether the user changing the configuration is permitted.", "name": "Azure domain federation settings modification attempt", "required_data": [ "AzureAD Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Azure Event Hub Deletion modified +1 −1
analytics/azure-event-hub-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection.","attackers_goals": "Evade detection.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An Azure event hub was deleted. An attacker might use this technique to evade detection.","description": "An Azure event hub was deleted. An attacker might use this technique to evade detection.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Check what actions were taken by the identity that deleted the event hub.","investigative_actions": "Check what actions were taken by the identity that deleted the event hub.","name": "Azure Event Hub Deletion","name": "Azure Event Hub Deletion","required_data": ["required_data": ["Azure Audit Log""Azure Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection.", "deduplication_period": "5 Days", "description": "An Azure event hub was deleted. An attacker might use this technique to evade detection.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Check what actions were taken by the identity that deleted the event hub.", "name": "Azure Event Hub Deletion", "required_data": [ "Azure Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ Azure Monitor alert rule deleted modified +1 −1
analytics/azure-monitor-alert-rule-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@"Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Tools (T1562.001)","Impair Defenses: Disable or Modify Tools (T1562.001)","Command and Scripting Interpreter: Cloud API (T1059.009)""Command and Scripting Interpreter: Cloud API (T1059.009)"],],"attackers_goals": "Blind defenders by removing alerts that watch for suspicious cloud activity. Avoid detection of subsequent operations such as data exfiltration, lateral movement, or persistence.","attackers_goals": "Blind defenders by removing alerts that watch for suspicious cloud activity. Avoid detection of subsequent operations such as data exfiltration, lateral movement, or persistence.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity.","description": "An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Identify which alert rule was deleted (metric, scheduled query, or activity-log alert) and what it was watching. Verify whether the identity that performed the deletion is authorized to manage Azure Monitor alert rules. Check the Azure Activity Log for the caller's other recent operations in the subscription / resource group. Look for correlated suspicious activity such as resource modifications, role assignments, or diagnostic-settings changes that would normally have been alerted on. Re-create the alert rule (or restore from infrastructure-as-code) to re-establish monitoring coverage.","investigative_actions": "Identify which alert rule was deleted (metric, scheduled query, or activity-log alert) and what it was watching. Verify whether the identity that performed the deletion is authorized to manage Azure Monitor alert rules. Check the Azure Activity Log for the caller's other recent operations in the subscription / resource group. Look for correlated suspicious activity such as resource modifications, role assignments, or diagnostic-settings changes that would normally have been alerted on. Re-create the alert rule (or restore from infrastructure-as-code) to re-establish monitoring coverage.","name": "Azure Monitor alert rule deleted","name": "Azure Monitor alert rule deleted","required_data": ["required_data": ["Azure Audit Log""Azure Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -8,17 +8,17 @@ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Tools (T1562.001)", "Command and Scripting Interpreter: Cloud API (T1059.009)" ], "attackers_goals": "Blind defenders by removing alerts that watch for suspicious cloud activity. Avoid detection of subsequent operations such as data exfiltration, lateral movement, or persistence.", "deduplication_period": "1 Day", "description": "An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Identify which alert rule was deleted (metric, scheduled query, or activity-log alert) and what it was watching. Verify whether the identity that performed the deletion is authorized to manage Azure Monitor alert rules. Check the Azure Activity Log for the caller's other recent operations in the subscription / resource group. Look for correlated suspicious activity such as resource modifications, role assignments, or diagnostic-settings changes that would normally have been alerted on. Re-create the alert rule (or restore from infrastructure-as-code) to re-establish monitoring coverage.", "name": "Azure Monitor alert rule deleted", "required_data": [ "Azure Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ Azure Network Watcher Deletion modified +1 −1
analytics/azure-network-watcher-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Avoid security mitigations and detections.","attackers_goals": "Avoid security mitigations and detections.","deduplication_period": "3 Hours","deduplication_period": "3 Hours","description": "Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations.","description": "Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Check which devices are monitored by the deleted Network Watcher.","investigative_actions": "Check which devices are monitored by the deleted Network Watcher.","name": "Azure Network Watcher Deletion","name": "Azure Network Watcher Deletion","required_data": ["required_data": ["Azure Audit Log""Azure Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Avoid security mitigations and detections.", "deduplication_period": "3 Hours", "description": "Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Check which devices are monitored by the deleted Network Watcher.", "name": "Azure Network Watcher Deletion", "required_data": [ "Azure Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ Azure service principal assigned app role modified +1 −1
analytics/azure-service-principal-assigned-app-roleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker may add roles to service principals that will allow them to access sensitive information and perform other actions.","attackers_goals": "An attacker may add roles to service principals that will allow them to access sensitive information and perform other actions.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity assigned an app role (permissions) to a service principal.","description": "An identity assigned an app role (permissions) to a service principal.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the added service principle is new to the organization. Check whether the account that added the app role is supposed to perform such actions. Check for possible logins and actions from the service principle with the role. Follow further actions done by the application and the assigner.","investigative_actions": "Check if the added service principle is new to the organization. Check whether the account that added the app role is supposed to perform such actions. Check for possible logins and actions from the service principle with the role. Follow further actions done by the application and the assigner.","name": "Azure service principal assigned app role","name": "Azure service principal assigned app role","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An attacker may add roles to service principals that will allow them to access sensitive information and perform other actions.", "deduplication_period": "1 Day", "description": "An identity assigned an app role (permissions) to a service principal.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the added service principle is new to the organization. Check whether the account that added the app role is supposed to perform such actions. Check for possible logins and actions from the service principle with the role. Follow further actions done by the application and the assigner.", "name": "Azure service principal assigned app role", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Azure Temporary Access Pass (TAP) registered to an account modified +1 −1
analytics/azure-temporary-access-pass-tap-registered-to-an-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "A TAP can allow setting of other authentication methods and can be used as an initial replacement of a multifactor authentication.","attackers_goals": "A TAP can allow setting of other authentication methods and can be used as an initial replacement of a multifactor authentication.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity registered an Azure Temporary Access Pass (TAP) to an account.","description": "An identity registered an Azure Temporary Access Pass (TAP) to an account.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the account that got the TAP should get it. Check whether the account that registered the TAP is supposed to perform such actions. Check if the TAP was registered to a privileged account. Follow further actions done by the initiator and the account with the TAP.","investigative_actions": "Check if the account that got the TAP should get it. Check whether the account that registered the TAP is supposed to perform such actions. Check if the TAP was registered to a privileged account. Follow further actions done by the initiator and the account with the TAP.","name": "Azure Temporary Access Pass (TAP) registered to an account","name": "Azure Temporary Access Pass (TAP) registered to an account","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "A TAP can allow setting of other authentication methods and can be used as an initial replacement of a multifactor authentication.", "deduplication_period": "1 Day", "description": "An identity registered an Azure Temporary Access Pass (TAP) to an account.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the account that got the TAP should get it. Check whether the account that registered the TAP is supposed to perform such actions. Check if the TAP was registered to a privileged account. Follow further actions done by the initiator and the account with the TAP.", "name": "Azure Temporary Access Pass (TAP) registered to an account", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ BitLocker key retrieval modified +1 −1
analytics/bitlocker-key-retrievalRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Abuse Elevation Control Mechanism (T1548)""Abuse Elevation Control Mechanism (T1548)"],],"attackers_goals": "BitLocker keys are used for mitigating unauthorized data access on lost or stolen computers by encrypting all user files and system files on the operating system drive. An attacker that retrieves this key, can potentially access the data that should be encrypted.","attackers_goals": "BitLocker keys are used for mitigating unauthorized data access on lost or stolen computers by encrypting all user files and system files on the operating system drive. An attacker that retrieves this key, can potentially access the data that should be encrypted.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity retrieved a BitLocker Key.","description": "An identity retrieved a BitLocker Key.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check what key was retrieved. Check for a possible compromised device. Check whether the user is permitted to perform such actions.","investigative_actions": "Check what key was retrieved. Check for a possible compromised device. Check whether the user is permitted to perform such actions.","name": "BitLocker key retrieval","name": "BitLocker key retrieval","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Abuse Elevation Control Mechanism (T1548)" ], "attackers_goals": "BitLocker keys are used for mitigating unauthorized data access on lost or stolen computers by encrypting all user files and system files on the operating system drive. An attacker that retrieves this key, can potentially access the data that should be encrypted.", "deduplication_period": "1 Day", "description": "An identity retrieved a BitLocker Key.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check what key was retrieved. Check for a possible compromised device. Check whether the user is permitted to perform such actions.", "name": "BitLocker key retrieval", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Chrome Extension Installed By User modified +1 −1
analytics/chrome-extension-installed-by-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Supply Chain Compromise: Compromise Software Dependencies and Development Tools (T1195.001)","Supply Chain Compromise: Compromise Software Dependencies and Development Tools (T1195.001)","Software Extensions: Browser Extensions (T1176.001)""Software Extensions: Browser Extensions (T1176.001)"],],"attackers_goals": "Adversaries may leverage browser extensions installation to gain Initial Access and Persistence, enabling them to intercept credentials and hijack active web sessions.","attackers_goals": "Adversaries may leverage browser extensions installation to gain Initial Access and Persistence, enabling them to intercept credentials and hijack active web sessions.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A Chrome extension was installed or updated by a Google Workspace user.","description": "A Chrome extension was installed or updated by a Google Workspace user.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Review the extension installed, it's OAuth scopes, reputation and permissions. Analyze subsequent network traffic from the user's device or browser for connections to newly registered domains. Investigate the source IP and identity for previous malicious activity or anomalies.","investigative_actions": "Review the extension installed, it's OAuth scopes, reputation and permissions. Analyze subsequent network traffic from the user's device or browser for connections to newly registered domains. Investigate the source IP and identity for previous malicious activity or anomalies.","name": "Chrome Extension Installed By User","name": "Chrome Extension Installed By User","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Supply Chain Compromise: Compromise Software Dependencies and Development Tools (T1195.001)", "Software Extensions: Browser Extensions (T1176.001)" ], "attackers_goals": "Adversaries may leverage browser extensions installation to gain Initial Access and Persistence, enabling them to intercept credentials and hijack active web sessions.", "deduplication_period": "1 Day", "description": "A Chrome extension was installed or updated by a Google Workspace user.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Review the extension installed, it's OAuth scopes, reputation and permissions. Analyze subsequent network traffic from the user's device or browser for connections to newly registered domains. Investigate the source IP and identity for previous malicious activity or anomalies.", "name": "Chrome Extension Installed By User", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Chrome OS Remote Access policy was modified in Google Workspace modified +1 −1
analytics/chrome-os-remote-access-policy-was-modified-in-google-workspaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Remote Services (T1021)""Remote Services (T1021)"],],"attackers_goals": "Adversaries may modify remote access settings to maintain persistent access and bypass security controls.","attackers_goals": "Adversaries may modify remote access settings to maintain persistent access and bypass security controls.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user modified Chrome OS Remote Access configuration in Google Workspace.","description": "A user modified Chrome OS Remote Access configuration in Google Workspace.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Verify if the configuration change was authorized. Investigate the source IP address and account involved for malicious activity. Follow further actions performed by the account and Remote Access connections performed.","investigative_actions": "Verify if the configuration change was authorized. Investigate the source IP address and account involved for malicious activity. Follow further actions performed by the account and Remote Access connections performed.","name": "Chrome OS Remote Access policy was modified in Google Workspace","name": "Chrome OS Remote Access policy was modified in Google Workspace","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Remote Services (T1021)" ], "attackers_goals": "Adversaries may modify remote access settings to maintain persistent access and bypass security controls.", "deduplication_period": "1 Day", "description": "A user modified Chrome OS Remote Access configuration in Google Workspace.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Verify if the configuration change was authorized. Investigate the source IP address and account involved for malicious activity. Follow further actions performed by the account and Remote Access connections performed.", "name": "Chrome OS Remote Access policy was modified in Google Workspace", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Cloud activity from a high-risk IP address modified +1 −1
analytics/cloud-activity-from-a-high-risk-ip-addressRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Proxy: Multi-hop Proxy (T1090.003)","Proxy: Multi-hop Proxy (T1090.003)","Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Gain initial access using a compromised identity while obfuscating origin.","attackers_goals": "Gain initial access using a compromised identity while obfuscating origin.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An identity executed a cloud API from a high-risk IP address.","description": "An identity executed a cloud API from a high-risk IP address.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Verify if the user is authorized to use anonymizing services. Review subsequent actions by the user for suspicious activity. Check for other users accessing from the same IP or tunnel operator.","investigative_actions": "Verify if the user is authorized to use anonymizing services. Review subsequent actions by the user for suspicious activity. Check for other users accessing from the same IP or tunnel operator.","name": "Cloud activity from a high-risk IP address","name": "Cloud activity from a high-risk IP address","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Proxy: Multi-hop Proxy (T1090.003)", "Valid Accounts (T1078)" ], "attackers_goals": "Gain initial access using a compromised identity while obfuscating origin.", "deduplication_period": "5 Days", "description": "An identity executed a cloud API from a high-risk IP address.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Verify if the user is authorized to use anonymizing services. Review subsequent actions by the user for suspicious activity. Check for other users accessing from the same IP or tunnel operator.", "name": "Cloud activity from a high-risk IP address", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "Informational", -
▸ ▾ Cloud user performed multiple actions that were denied modified +1 −1
analytics/cloud-user-performed-multiple-actions-that-were-deniedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Account Discovery (T1087)","Account Discovery (T1087)","Permission Groups Discovery (T1069)""Permission Groups Discovery (T1069)"],],"attackers_goals": "Execute various commands to explore the cloud environment.","attackers_goals": "Execute various commands to explore the cloud environment.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An identity performed multiple actions that were denied, which may indicate it is being misused.","description": "An identity performed multiple actions that were denied, which may indicate it is being misused.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Check if the API calls were made by the identity. Check if there are additional calls executed by the identity.","investigative_actions": "Check if the API calls were made by the identity. Check if there are additional calls executed by the identity.","name": "Cloud user performed multiple actions that were denied","name": "Cloud user performed multiple actions that were denied","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Account Discovery (T1087)", "Permission Groups Discovery (T1069)" ], "attackers_goals": "Execute various commands to explore the cloud environment.", "deduplication_period": "5 Days", "description": "An identity performed multiple actions that were denied, which may indicate it is being misused.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Check if the API calls were made by the identity. Check if there are additional calls executed by the identity.", "name": "Cloud user performed multiple actions that were denied", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "Informational", -
▸ ▾ CloudTrail logging deletion modified +1 −1
analytics/cloudtrail-logging-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection by limiting collected data.","attackers_goals": "Evade detection by limiting collected data.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "CloudTrail logging trail deletion.","description": "CloudTrail logging trail deletion.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Verify whether the identity attempted to delete the trail. Determine whether an additional trail needs to be enabled.","investigative_actions": "Verify whether the identity attempted to delete the trail. Determine whether an additional trail needs to be enabled.","name": "CloudTrail logging deletion","name": "CloudTrail logging deletion","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection by limiting collected data.", "deduplication_period": "5 Days", "description": "CloudTrail logging trail deletion.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Verify whether the identity attempted to delete the trail. Determine whether an additional trail needs to be enabled.", "name": "CloudTrail logging deletion", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ Compute activity in dormant cloud region modified +1 −1
analytics/compute-activity-in-dormant-cloud-regionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Unused/Unsupported Cloud Regions (T1535)""Unused/Unsupported Cloud Regions (T1535)"],],"attackers_goals": "Create compute resources in unmonitored regions to evade detection for purposes such as hijacking resources or establishing persistence.","attackers_goals": "Create compute resources in unmonitored regions to evade detection for purposes such as hijacking resources or establishing persistence.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A compute resource was created or updated in a cloud region that has been dormant for this project.","description": "A compute resource was created or updated in a cloud region that has been dormant for this project.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Verify if compute resources are authorized in this region. Terminate unauthorized compute resources and disable unused regions.","investigative_actions": "Verify if compute resources are authorized in this region. Terminate unauthorized compute resources and disable unused regions.","name": "Compute activity in dormant cloud region","name": "Compute activity in dormant cloud region","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Unused/Unsupported Cloud Regions (T1535)" ], "attackers_goals": "Create compute resources in unmonitored regions to evade detection for purposes such as hijacking resources or establishing persistence.", "deduplication_period": "5 Days", "description": "A compute resource was created or updated in a cloud region that has been dormant for this project.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Verify if compute resources are authorized in this region. Terminate unauthorized compute resources and disable unused regions.", "name": "Compute activity in dormant cloud region", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "Informational", -
▸ ▾ Conditional Access policy removed modified +1 −1
analytics/conditional-access-policy-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Abuse Elevation Control Mechanism (T1548)""Abuse Elevation Control Mechanism (T1548)"],],"attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. Without a Conditional Access policy, an attacker would be able to access the tenant without possible blockage for later access.","attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. Without a Conditional Access policy, an attacker would be able to access the tenant without possible blockage for later access.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity removed a Conditional Access policy.","description": "An identity removed a Conditional Access policy.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check implications of the policy being removed. Check whether the user changing the configuration is permitted to perform such actions.","investigative_actions": "Check implications of the policy being removed. Check whether the user changing the configuration is permitted to perform such actions.","name": "Conditional Access policy removed","name": "Conditional Access policy removed","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Abuse Elevation Control Mechanism (T1548)" ], "attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. Without a Conditional Access policy, an attacker would be able to access the tenant without possible blockage for later access.", "deduplication_period": "1 Day", "description": "An identity removed a Conditional Access policy.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check implications of the policy being removed. Check whether the user changing the configuration is permitted to perform such actions.", "name": "Conditional Access policy removed", "required_data": [ "AzureAD Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Data Sharing between GCP and Google Workspace was disabled modified +1 −1
analytics/data-sharing-between-gcp-and-google-workspace-was-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@"Indicator Removal (T1070)","Indicator Removal (T1070)","Impair Defenses (T1562)","Impair Defenses (T1562)","Data Manipulation (T1565)","Data Manipulation (T1565)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Adversaries may stop audit log events from being sent to remove evidence of their presence or hinder defenses.","attackers_goals": "Adversaries may stop audit log events from being sent to remove evidence of their presence or hinder defenses.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "An identity has modified data sharing settings between GCP and Google Workspace.","description": "An identity has modified data sharing settings between GCP and Google Workspace.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check whether Google Workspace audit log events were configured to be sent to Google Cloud. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check whether Google Workspace audit log events were configured to be sent to Google Cloud. Follow further actions done by the account.","name": "Data Sharing between GCP and Google Workspace was disabled","name": "Data Sharing between GCP and Google Workspace was disabled","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -8,17 +8,17 @@ "Indicator Removal (T1070)", "Impair Defenses (T1562)", "Data Manipulation (T1565)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Adversaries may stop audit log events from being sent to remove evidence of their presence or hinder defenses.", "deduplication_period": "2 Days", "description": "An identity has modified data sharing settings between GCP and Google Workspace.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check whether Google Workspace audit log events were configured to be sent to Google Cloud. Follow further actions done by the account.", "name": "Data Sharing between GCP and Google Workspace was disabled", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Deletion of multiple cloud resources modified +1 −1
analytics/deletion-of-multiple-cloud-resourcesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Data Destruction (T1485)""Data Destruction (T1485)"],],"attackers_goals": "Leverage access to the cloud to delete resources and cause damage to an organization's infrastructure.","attackers_goals": "Leverage access to the cloud to delete resources and cause damage to an organization's infrastructure.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An identity deleted multiple cloud resources.","description": "An identity deleted multiple cloud resources.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Confirm the legitimacy of the suspected identity and what cloud resources have been deleted by the identity. Look for any unusual activity associated with the suspected identity and determine whether they are compromised.","investigative_actions": "Confirm the legitimacy of the suspected identity and what cloud resources have been deleted by the identity. Look for any unusual activity associated with the suspected identity and determine whether they are compromised.","name": "Deletion of multiple cloud resources","name": "Deletion of multiple cloud resources","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Data Destruction (T1485)" ], "attackers_goals": "Leverage access to the cloud to delete resources and cause damage to an organization's infrastructure.", "deduplication_period": "5 Days", "description": "An identity deleted multiple cloud resources.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Confirm the legitimacy of the suspected identity and what cloud resources have been deleted by the identity. Look for any unusual activity associated with the suspected identity and determine whether they are compromised.", "name": "Deletion of multiple cloud resources", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "Informational", -
▸ ▾ Device Registration Policy modification modified +1 −1
analytics/device-registration-policy-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Abuse Elevation Control Mechanism (T1548)""Abuse Elevation Control Mechanism (T1548)"],],"attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. With a modified Device Registration policy, an attacker might be able to access the tenant without possible blockage for later access.","attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. With a modified Device Registration policy, an attacker might be able to access the tenant without possible blockage for later access.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity changed the Device Registration policy.","description": "An identity changed the Device Registration policy.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check what policy has been changed. Check whether the user changing the configuration is permitted to perform such actions.","investigative_actions": "Check what policy has been changed. Check whether the user changing the configuration is permitted to perform such actions.","name": "Device Registration Policy modification","name": "Device Registration Policy modification","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Abuse Elevation Control Mechanism (T1548)" ], "attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. With a modified Device Registration policy, an attacker might be able to access the tenant without possible blockage for later access.", "deduplication_period": "1 Day", "description": "An identity changed the Device Registration policy.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check what policy has been changed. Check whether the user changing the configuration is permitted to perform such actions.", "name": "Device Registration Policy modification", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Disable AWS audit logs through Event Selectors modified +1 −1
analytics/disable-aws-audit-logs-through-event-selectorsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection by filtering out audit logs.","attackers_goals": "Evade detection by filtering out audit logs.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs.","description": "An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Review the new event selector policy. Check The cloud identity activity prior/after to the event selectors policy modification.","investigative_actions": "Review the new event selector policy. Check The cloud identity activity prior/after to the event selectors policy modification.","name": "Disable AWS audit logs through Event Selectors","name": "Disable AWS audit logs through Event Selectors","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection by filtering out audit logs.", "deduplication_period": "1 Day", "description": "An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Review the new event selector policy. Check The cloud identity activity prior/after to the event selectors policy modification.", "name": "Disable AWS audit logs through Event Selectors", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ DLP sensitive data exposed to external users modified +1 −1
analytics/dlp-sensitive-data-exposed-to-external-usersRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Data from Information Repositories: Sharepoint (T1213.002)","Data from Information Repositories: Sharepoint (T1213.002)","Data from Information Repositories (T1213)""Data from Information Repositories (T1213)"],],"attackers_goals": "An attacker is attempting to access sensitive information.","attackers_goals": "An attacker is attempting to access sensitive information.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information.","description": "A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "O365 DLP Analytics, Data Detection & Response","detector_tags": "O365 DLP Analytics, Data Detection & Response","investigative_actions": "Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.","investigative_actions": "Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.","name": "DLP sensitive data exposed to external users","name": "DLP sensitive data exposed to external users","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Data from Information Repositories: Sharepoint (T1213.002)", "Data from Information Repositories (T1213)" ], "attackers_goals": "An attacker is attempting to access sensitive information.", "deduplication_period": "1 Day", "description": "A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "O365 DLP Analytics, Data Detection & Response", "investigative_actions": "Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.", "name": "DLP sensitive data exposed to external users", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Exchange anti-phish policy disabled or removed modified +1 −1
analytics/exchange-anti-phish-policy-disabled-or-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses: Disable or Modify Tools (T1562.001)","Impair Defenses: Disable or Modify Tools (T1562.001)","Phishing (T1566)""Phishing (T1566)"],],"attackers_goals": "An attacker is attempting to evade detection.","attackers_goals": "An attacker is attempting to evade detection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign.","description": "A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.","name": "Exchange anti-phish policy disabled or removed","name": "Exchange anti-phish policy disabled or removed","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Impair Defenses: Disable or Modify Tools (T1562.001)", "Phishing (T1566)" ], "attackers_goals": "An attacker is attempting to evade detection.", "deduplication_period": "1 Day", "description": "A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.", "name": "Exchange anti-phish policy disabled or removed", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Exchange audit log disabled modified +1 −1
analytics/exchange-audit-log-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "An attacker is attempting to evade detection.","attackers_goals": "An attacker is attempting to evade detection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user disabled the Exchange audit log. This may indicate an attempt to evade detection.","description": "A user disabled the Exchange audit log. This may indicate an attempt to evade detection.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).","name": "Exchange audit log disabled","name": "Exchange audit log disabled","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "An attacker is attempting to evade detection.", "deduplication_period": "1 Day", "description": "A user disabled the Exchange audit log. This may indicate an attempt to evade detection.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).", "name": "Exchange audit log disabled", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Exchange compliance search created modified +1 −1
analytics/exchange-compliance-search-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Collection (TA0009)""Collection (TA0009)"],],"attack_techniques": ["attack_techniques": ["Email Collection (T1114)""Email Collection (T1114)"],],"attackers_goals": "An attacker is searching mailboxes to access sensitive information.","attackers_goals": "An attacker is searching mailboxes to access sensitive information.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization.","description": "A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Check to see if the search contained sensitive information. Check if any data was exfiltrated after the search. Look for suspicious search terms.","investigative_actions": "Follow further actions done by the account. Check to see if the search contained sensitive information. Check if any data was exfiltrated after the search. Look for suspicious search terms.","name": "Exchange compliance search created","name": "Exchange compliance search created","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Collection (TA0009)" ], "attack_techniques": [ "Email Collection (T1114)" ], "attackers_goals": "An attacker is searching mailboxes to access sensitive information.", "deduplication_period": "1 Day", "description": "A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Check to see if the search contained sensitive information. Check if any data was exfiltrated after the search. Look for suspicious search terms.", "name": "Exchange compliance search created", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Exchange DKIM signing configuration disabled modified +1 −1
analytics/exchange-dkim-signing-configuration-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses: Disable or Modify Tools (T1562.001)","Impair Defenses: Disable or Modify Tools (T1562.001)","Phishing (T1566)""Phishing (T1566)"],],"attackers_goals": "An attacker is attempting to evade detection.","attackers_goals": "An attacker is attempting to evade detection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed.","description": "A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.","name": "Exchange DKIM signing configuration disabled","name": "Exchange DKIM signing configuration disabled","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Impair Defenses: Disable or Modify Tools (T1562.001)", "Phishing (T1566)" ], "attackers_goals": "An attacker is attempting to evade detection.", "deduplication_period": "1 Day", "description": "A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.", "name": "Exchange DKIM signing configuration disabled", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Exchange email-hiding inbox rule modified +1 −1
analytics/exchange-email-hiding-inbox-ruleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Hide Artifacts: Email Hiding Rules (T1564.008)""Hide Artifacts: Email Hiding Rules (T1564.008)"],],"attackers_goals": "Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).","attackers_goals": "Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user configured an Exchange inbox rule that may be used to hide emails.","description": "A user configured an Exchange inbox rule that may be used to hide emails.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule keywords look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for multiple instances of email hiding, which may be an indication of a larger campaign. Check if the user regularly configures inbox rules.","investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule keywords look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for multiple instances of email hiding, which may be an indication of a larger campaign. Check if the user regularly configures inbox rules.","name": "Exchange email-hiding inbox rule","name": "Exchange email-hiding inbox rule","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Hide Artifacts: Email Hiding Rules (T1564.008)" ], "attackers_goals": "Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).", "deduplication_period": "1 Day", "description": "A user configured an Exchange inbox rule that may be used to hide emails.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule keywords look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for multiple instances of email hiding, which may be an indication of a larger campaign. Check if the user regularly configures inbox rules.", "name": "Exchange email-hiding inbox rule", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Exchange email-hiding transport rule modified +1 −1
analytics/exchange-email-hiding-transport-ruleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Hide Artifacts: Email Hiding Rules (T1564.008)""Hide Artifacts: Email Hiding Rules (T1564.008)"],],"attackers_goals": "Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).","attackers_goals": "Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user configured an Exchange transport rule that may be used to hide emails in the organization.","description": "A user configured an Exchange transport rule that may be used to hide emails in the organization.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule contains keywords and if they look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization.* Look for multiple instances of email hiding, which may be an indication of a larger campaign.* Check if the user regularly configures transport rules.","investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule contains keywords and if they look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization.* Look for multiple instances of email hiding, which may be an indication of a larger campaign.* Check if the user regularly configures transport rules.","name": "Exchange email-hiding transport rule","name": "Exchange email-hiding transport rule","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Hide Artifacts: Email Hiding Rules (T1564.008)" ], "attackers_goals": "Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).", "deduplication_period": "1 Day", "description": "A user configured an Exchange transport rule that may be used to hide emails in the organization.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule contains keywords and if they look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization.* Look for multiple instances of email hiding, which may be an indication of a larger campaign.* Check if the user regularly configures transport rules.", "name": "Exchange email-hiding transport rule", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Exchange inbox forwarding rule configured modified +1 −1
analytics/exchange-inbox-forwarding-rule-configuredRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Email Collection: Email Forwarding Rule (T1114.003)","Email Collection: Email Forwarding Rule (T1114.003)","Automated Exfiltration (T1020)","Automated Exfiltration (T1020)","Email Collection (T1114)""Email Collection (T1114)"],],"attackers_goals": "Create an inbox rule using a compromised user account to automatically forward emails containing specific conditions to an external recipient.","attackers_goals": "Create an inbox rule using a compromised user account to automatically forward emails containing specific conditions to an external recipient.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions.","description": "A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Check what conditions are met in the inbox rule (e.g. specific keywords in the subject or body). Determine if any of the conditions and keywords look suspicious. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for emails sent to this recipient by other users.","investigative_actions": "Check what conditions are met in the inbox rule (e.g. specific keywords in the subject or body). Determine if any of the conditions and keywords look suspicious. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for emails sent to this recipient by other users.","name": "Exchange inbox forwarding rule configured","name": "Exchange inbox forwarding rule configured","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Email Collection: Email Forwarding Rule (T1114.003)", "Automated Exfiltration (T1020)", "Email Collection (T1114)" ], "attackers_goals": "Create an inbox rule using a compromised user account to automatically forward emails containing specific conditions to an external recipient.", "deduplication_period": "1 Day", "description": "A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Check what conditions are met in the inbox rule (e.g. specific keywords in the subject or body). Determine if any of the conditions and keywords look suspicious. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for emails sent to this recipient by other users.", "name": "Exchange inbox forwarding rule configured", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Exchange mailbox audit bypass modified +1 −1
analytics/exchange-mailbox-audit-bypassRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Tools (T1562.001)""Impair Defenses: Disable or Modify Tools (T1562.001)"],],"attackers_goals": "An attacker may abuse the audit bypass mechanism to conceal actions and evade detection.","attackers_goals": "An attacker may abuse the audit bypass mechanism to conceal actions and evade detection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection.","description": "A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected.","name": "Exchange mailbox audit bypass","name": "Exchange mailbox audit bypass","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Tools (T1562.001)" ], "attackers_goals": "An attacker may abuse the audit bypass mechanism to conceal actions and evade detection.", "deduplication_period": "1 Day", "description": "A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected.", "name": "Exchange mailbox audit bypass", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Exchange mailbox delegation permissions added modified +1 −1
analytics/exchange-mailbox-delegation-permissions-addedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation: Additional Email Delegate Permissions (T1098.002)""Account Manipulation: Additional Email Delegate Permissions (T1098.002)"],],"attackers_goals": "Add delegation permissions to a mailbox for persistence reasons.","attackers_goals": "Add delegation permissions to a mailbox for persistence reasons.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user added delegation permissions to an Exchange mailbox.","description": "A user added delegation permissions to an Exchange mailbox.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents).","investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents).","name": "Exchange mailbox delegation permissions added","name": "Exchange mailbox delegation permissions added","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "4 Hours","test_period": "4 Hours",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Account Manipulation: Additional Email Delegate Permissions (T1098.002)" ], "attackers_goals": "Add delegation permissions to a mailbox for persistence reasons.", "deduplication_period": "1 Day", "description": "A user added delegation permissions to an Exchange mailbox.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents).", "name": "Exchange mailbox delegation permissions added", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "4 Hours", -
▸ ▾ Exchange mailbox folder permission modification modified +1 −1
analytics/exchange-mailbox-folder-permission-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation: Additional Email Delegate Permissions (T1098.002)""Account Manipulation: Additional Email Delegate Permissions (T1098.002)"],],"attackers_goals": "An attacker may add permissions to a mailbox folder for persistence reasons. For instance, an attacker may assign the Default or Anonymous user permissions. This will allow them to maintain persistent access to the mailbox folder, which may lead to exfiltration of the messages.","attackers_goals": "An attacker may add permissions to a mailbox folder for persistence reasons. For instance, an attacker may assign the Default or Anonymous user permissions. This will allow them to maintain persistent access to the mailbox folder, which may lead to exfiltration of the messages.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user modified permissions to an Exchange mailbox folder.","description": "A user modified permissions to an Exchange mailbox folder.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Check for abnormal Azure AD non-interactive logins by the user. Monitor for changes that may indicate excessively broad permissions.","investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Check for abnormal Azure AD non-interactive logins by the user. Monitor for changes that may indicate excessively broad permissions.","name": "Exchange mailbox folder permission modification","name": "Exchange mailbox folder permission modification","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Account Manipulation: Additional Email Delegate Permissions (T1098.002)" ], "attackers_goals": "An attacker may add permissions to a mailbox folder for persistence reasons. For instance, an attacker may assign the Default or Anonymous user permissions. This will allow them to maintain persistent access to the mailbox folder, which may lead to exfiltration of the messages.", "deduplication_period": "1 Day", "description": "A user modified permissions to an Exchange mailbox folder.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Check for abnormal Azure AD non-interactive logins by the user. Monitor for changes that may indicate excessively broad permissions.", "name": "Exchange mailbox folder permission modification", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Exchange malware filter policy removed modified +1 −1
analytics/exchange-malware-filter-policy-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Tools (T1562.001)""Impair Defenses: Disable or Modify Tools (T1562.001)"],],"attackers_goals": "An attacker is attempting to evade detection.","attackers_goals": "An attacker is attempting to evade detection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user removed an Exchange malware filter policy, which may prevent the detection of malware.","description": "A user removed an Exchange malware filter policy, which may prevent the detection of malware.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other security policies have been changed or removed. Monitor for signs of malware in future messages.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other security policies have been changed or removed. Monitor for signs of malware in future messages.","name": "Exchange malware filter policy removed","name": "Exchange malware filter policy removed","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Tools (T1562.001)" ], "attackers_goals": "An attacker is attempting to evade detection.", "deduplication_period": "1 Day", "description": "A user removed an Exchange malware filter policy, which may prevent the detection of malware.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other security policies have been changed or removed. Monitor for signs of malware in future messages.", "name": "Exchange malware filter policy removed", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Exchange Safe Attachment policy disabled or removed modified +1 −1
analytics/exchange-safe-attachment-policy-disabled-or-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses: Disable or Modify Tools (T1562.001)","Impair Defenses: Disable or Modify Tools (T1562.001)","Phishing: Spearphishing Attachment (T1566.001)""Phishing: Spearphishing Attachment (T1566.001)"],],"attackers_goals": "An attacker may attempt to disable the Safe Attachment policy to evade detection.","attackers_goals": "An attacker may attempt to disable the Safe Attachment policy to evade detection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments.","description": "A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.","name": "Exchange Safe Attachment policy disabled or removed","name": "Exchange Safe Attachment policy disabled or removed","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Impair Defenses: Disable or Modify Tools (T1562.001)", "Phishing: Spearphishing Attachment (T1566.001)" ], "attackers_goals": "An attacker may attempt to disable the Safe Attachment policy to evade detection.", "deduplication_period": "1 Day", "description": "A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.", "name": "Exchange Safe Attachment policy disabled or removed", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Exchange Safe Link policy disabled or removed modified +1 −1
analytics/exchange-safe-link-policy-disabled-or-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses: Disable or Modify Tools (T1562.001)","Impair Defenses: Disable or Modify Tools (T1562.001)","Phishing: Spearphishing Link (T1566.002)""Phishing: Spearphishing Link (T1566.002)"],],"attackers_goals": "An attacker is attempting to bypass security measures associated with hyperlinks in email messages.","attackers_goals": "An attacker is attempting to bypass security measures associated with hyperlinks in email messages.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks.","description": "A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for email messages received with hyperlinks. Check for a possible phishing campaign on the organization.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for email messages received with hyperlinks. Check for a possible phishing campaign on the organization.","name": "Exchange Safe Link policy disabled or removed","name": "Exchange Safe Link policy disabled or removed","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Impair Defenses: Disable or Modify Tools (T1562.001)", "Phishing: Spearphishing Link (T1566.002)" ], "attackers_goals": "An attacker is attempting to bypass security measures associated with hyperlinks in email messages.", "deduplication_period": "1 Day", "description": "A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for email messages received with hyperlinks. Check for a possible phishing campaign on the organization.", "name": "Exchange Safe Link policy disabled or removed", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Exchange transport forwarding rule configured modified +1 −1
analytics/exchange-transport-forwarding-rule-configuredRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Email Collection: Email Forwarding Rule (T1114.003)","Email Collection: Email Forwarding Rule (T1114.003)","Automated Exfiltration (T1020)","Automated Exfiltration (T1020)","Email Collection (T1114)""Email Collection (T1114)"],],"attackers_goals": "Forward all emails in the organization that match specific criteria to an external recipient to collect sensitive information.","attackers_goals": "Forward all emails in the organization that match specific criteria to an external recipient to collect sensitive information.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization.","description": "A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Check what mailboxes are affected by the transport rule. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for emails sent to this recipient by other users.","investigative_actions": "Check what mailboxes are affected by the transport rule. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for emails sent to this recipient by other users.","name": "Exchange transport forwarding rule configured","name": "Exchange transport forwarding rule configured","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Email Collection: Email Forwarding Rule (T1114.003)", "Automated Exfiltration (T1020)", "Email Collection (T1114)" ], "attackers_goals": "Forward all emails in the organization that match specific criteria to an external recipient to collect sensitive information.", "deduplication_period": "1 Day", "description": "A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Check what mailboxes are affected by the transport rule. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain and look up its reputation. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for emails sent to this recipient by other users.", "name": "Exchange transport forwarding rule configured", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Exchange user mailbox forwarding modified +1 −1
analytics/exchange-user-mailbox-forwardingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Email Collection: Email Forwarding Rule (T1114.003)","Email Collection: Email Forwarding Rule (T1114.003)","Automated Exfiltration (T1020)","Automated Exfiltration (T1020)","Email Collection (T1114)""Email Collection (T1114)"],],"attackers_goals": "Leverage a compromised user account to modify a mailbox's settings to forward emails to an external recipient and collect sensitive information.","attackers_goals": "Leverage a compromised user account to modify a mailbox's settings to forward emails to an external recipient and collect sensitive information.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient.","description": "A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain. Investigate the IP address associated with the rule. Follow further actions done by the account.","investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain. Investigate the IP address associated with the rule. Follow further actions done by the account.","name": "Exchange user mailbox forwarding","name": "Exchange user mailbox forwarding","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Email Collection: Email Forwarding Rule (T1114.003)", "Automated Exfiltration (T1020)", "Email Collection (T1114)" ], "attackers_goals": "Leverage a compromised user account to modify a mailbox's settings to forward emails to an external recipient and collect sensitive information.", "deduplication_period": "1 Day", "description": "A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain. Investigate the IP address associated with the rule. Follow further actions done by the account.", "name": "Exchange user mailbox forwarding", "required_data": [ "Office 365 Audit" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ External SaaS file-sharing activity modified +1 −1
analytics/external-saas-file-sharing-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Collection (TA0009)""Collection (TA0009)"],],"attack_techniques": ["attack_techniques": ["Data from Cloud Storage (T1530)""Data from Cloud Storage (T1530)"],],"attackers_goals": "An attacker may share files from a SaaS service to exfiltrate sensitive data.","attackers_goals": "An attacker may share files from a SaaS service to exfiltrate sensitive data.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user shared files from within a SaaS service to an external domain.","description": "A user shared files from within a SaaS service to an external domain.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Data Detection & Response","detector_tags": "Data Detection & Response","investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Determine if the files are shared with users outside the organization and if the recipients are familiar. Review the files that were shared to determine if they contain sensitive data. Analyze the file types that were shared. Monitor the account for any further suspicious actions.","investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Determine if the files are shared with users outside the organization and if the recipients are familiar. Review the files that were shared to determine if they contain sensitive data. Analyze the file types that were shared. Monitor the account for any further suspicious actions.","name": "External SaaS file-sharing activity","name": "External SaaS file-sharing activity","required_data": ["required_data": ["Box Audit Log","Box Audit Log","DropBox","DropBox","Google Workspace Audit Logs","Google Workspace Audit Logs","Office 365 Audit""Office 365 Audit"Show markdown source
@@ -4,17 +4,17 @@ "Collection (TA0009)" ], "attack_techniques": [ "Data from Cloud Storage (T1530)" ], "attackers_goals": "An attacker may share files from a SaaS service to exfiltrate sensitive data.", "deduplication_period": "1 Day", "description": "A user shared files from within a SaaS service to an external domain.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Data Detection & Response", "investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Determine if the files are shared with users outside the organization and if the recipients are familiar. Review the files that were shared to determine if they contain sensitive data. Analyze the file types that were shared. Monitor the account for any further suspicious actions.", "name": "External SaaS file-sharing activity", "required_data": [ "Box Audit Log", "DropBox", "Google Workspace Audit Logs", "Office 365 Audit" -
▸ ▾ External Sharing was turned on for Google Drive modified +1 −1
analytics/external-sharing-was-turned-on-for-google-driveRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Exfiltration (TA0010)""Exfiltration (TA0010)"],],"attack_techniques": ["attack_techniques": ["Transfer Data to Cloud Account (T1537)""Transfer Data to Cloud Account (T1537)"],],"attackers_goals": "Adversaries may exfiltrate data, such as sensitive documents.","attackers_goals": "Adversaries may exfiltrate data, such as sensitive documents.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An identity has modified Google Drive sharing settings and allowed external sharing.","description": "An identity has modified Google Drive sharing settings and allowed external sharing.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). check the new setting details. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). check the new setting details. Follow further actions done by the account.","name": "External Sharing was turned on for Google Drive","name": "External Sharing was turned on for Google Drive","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Exfiltration (TA0010)" ], "attack_techniques": [ "Transfer Data to Cloud Account (T1537)" ], "attackers_goals": "Adversaries may exfiltrate data, such as sensitive documents.", "deduplication_period": "5 Days", "description": "An identity has modified Google Drive sharing settings and allowed external sharing.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). check the new setting details. Follow further actions done by the account.", "name": "External Sharing was turned on for Google Drive", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ External user added a link to a Microsoft Teams chat modified +1 −1
analytics/external-user-added-a-link-to-a-microsoft-teams-chatRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Phishing (T1566)""Phishing (T1566)"],],"attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.","attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An external user added a link to a Microsoft Teams chat.","description": "An external user added a link to a Microsoft Teams chat.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the external tenant and user are authorized to share links or files with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that have been sent in the conversation. Evaluate the external domain reputation. Review past communication from the external user. Follow further actions done by the account.","investigative_actions": "Confirm that the external tenant and user are authorized to share links or files with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that have been sent in the conversation. Evaluate the external domain reputation. Review past communication from the external user. Follow further actions done by the account.","name": "External user added a link to a Microsoft Teams chat","name": "External user added a link to a Microsoft Teams chat","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Phishing (T1566)" ], "attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.", "deduplication_period": "1 Day", "description": "An external user added a link to a Microsoft Teams chat.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the external tenant and user are authorized to share links or files with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that have been sent in the conversation. Evaluate the external domain reputation. Review past communication from the external user. Follow further actions done by the account.", "name": "External user added a link to a Microsoft Teams chat", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ External user call via Microsoft Teams modified +1 −1
analytics/external-user-call-via-microsoft-teamsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Phishing: Spearphishing Voice (T1566.004)""Phishing: Spearphishing Voice (T1566.004)"],],"attackers_goals": "Attackers may leverage Microsoft Teams to conduct voice phishing attacks by exploiting trusted communication channels with users inside the organization.","attackers_goals": "Attackers may leverage Microsoft Teams to conduct voice phishing attacks by exploiting trusted communication channels with users inside the organization.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An external user called a user in the organization via Microsoft Teams.","description": "An external user called a user in the organization via Microsoft Teams.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the external tenant and external user are authorized to call users in the organization. Check external domain reputation. Follow further actions performed by the user who participated in the call. Verify if the user account was compromised or was a victim of a voice phishing campaign.","investigative_actions": "Confirm that the external tenant and external user are authorized to call users in the organization. Check external domain reputation. Follow further actions performed by the user who participated in the call. Verify if the user account was compromised or was a victim of a voice phishing campaign.","name": "External user call via Microsoft Teams","name": "External user call via Microsoft Teams","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "10 Minutes","test_period": "10 Minutes",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Phishing: Spearphishing Voice (T1566.004)" ], "attackers_goals": "Attackers may leverage Microsoft Teams to conduct voice phishing attacks by exploiting trusted communication channels with users inside the organization.", "deduplication_period": "1 Day", "description": "An external user called a user in the organization via Microsoft Teams.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the external tenant and external user are authorized to call users in the organization. Check external domain reputation. Follow further actions performed by the user who participated in the call. Verify if the user account was compromised or was a victim of a voice phishing campaign.", "name": "External user call via Microsoft Teams", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "10 Minutes", -
▸ ▾ External user created a Microsoft Teams conversation with suspicious operations modified +1 −1
analytics/external-user-created-a-microsoft-teams-conversation-with-suspicious-operationsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Phishing (T1566)""Phishing (T1566)"],],"attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.","attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations.","description": "An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the tenant and user are authorized to start a conversation with users in the organization. Verify whether any user was removed from the conversation, and determine the reason for their removal. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that might have been sent in the conversation. Check external domain reputation. Review past communication from the external user. Follow further actions done by the account.","investigative_actions": "Confirm that the tenant and user are authorized to start a conversation with users in the organization. Verify whether any user was removed from the conversation, and determine the reason for their removal. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that might have been sent in the conversation. Check external domain reputation. Review past communication from the external user. Follow further actions done by the account.","name": "External user created a Microsoft Teams conversation with suspicious operations","name": "External user created a Microsoft Teams conversation with suspicious operations","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "3 Hours","test_period": "3 Hours",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Phishing (T1566)" ], "attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.", "deduplication_period": "1 Day", "description": "An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the tenant and user are authorized to start a conversation with users in the organization. Verify whether any user was removed from the conversation, and determine the reason for their removal. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that might have been sent in the conversation. Check external domain reputation. Review past communication from the external user. Follow further actions done by the account.", "name": "External user created a Microsoft Teams conversation with suspicious operations", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "3 Hours", -
▸ ▾ External user started a Microsoft Teams conversation modified +1 −1
analytics/external-user-started-a-microsoft-teams-conversationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Phishing (T1566)""Phishing (T1566)"],],"attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.","attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An external user started a Microsoft Teams conversation with users in the organization.","description": "An external user started a Microsoft Teams conversation with users in the organization.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the tenant and user are authorized to start a conversation with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that might have been sent in the conversation. Check external domain reputation. Review past communication from the external user. Follow further actions done by the account.","investigative_actions": "Confirm that the tenant and user are authorized to start a conversation with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that might have been sent in the conversation. Check external domain reputation. Review past communication from the external user. Follow further actions done by the account.","name": "External user started a Microsoft Teams conversation","name": "External user started a Microsoft Teams conversation","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Phishing (T1566)" ], "attackers_goals": "Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.", "deduplication_period": "1 Day", "description": "An external user started a Microsoft Teams conversation with users in the organization.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the tenant and user are authorized to start a conversation with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that might have been sent in the conversation. Check external domain reputation. Review past communication from the external user. Follow further actions done by the account.", "name": "External user started a Microsoft Teams conversation", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ First Azure AD PowerShell operation for a user modified +1 −1
analytics/first-azure-ad-powershell-operation-for-a-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Achieve initial access to a company's resources.","attackers_goals": "Achieve initial access to a company's resources.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user performed an Azure AD operation using a PowerShell user-agent for the first time.","description": "A user performed an Azure AD operation using a PowerShell user-agent for the first time.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Follow the actions the user performed using PowerShell. Confirm with the user that the action was intended.","investigative_actions": "Follow the actions the user performed using PowerShell. Confirm with the user that the action was intended.","name": "First Azure AD PowerShell operation for a user","name": "First Azure AD PowerShell operation for a user","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "Achieve initial access to a company's resources.", "deduplication_period": "1 Day", "description": "A user performed an Azure AD operation using a PowerShell user-agent for the first time.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Follow the actions the user performed using PowerShell. Confirm with the user that the action was intended.", "name": "First Azure AD PowerShell operation for a user", "required_data": [ "AzureAD Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ First-time directory sync of an on-premises domain user to an existing cloud account modified +1 −1
analytics/first-time-directory-sync-of-an-on-premises-domain-user-to-an-existing-cloud-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Attackers may leverage DirectorySync to move laterally from a compromised on-premise environment into the cloud tenant, allowing them to bypass the cloud's security boundaries and take over high-value cloud identities.","attackers_goals": "Attackers may leverage DirectorySync to move laterally from a compromised on-premise environment into the cloud tenant, allowing them to bypass the cloud's security boundaries and take over high-value cloud identities.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "First-time synchronization of an on-premises domain user with an existing cloud account.","description": "First-time synchronization of an on-premises domain user with an existing cloud account.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the cloud account was an administrator (Global Admin, etc.) before this sync. Determine if the on-premise user was recently created or if its 'proxyAddress' attribute was recently modified. Confirm if the organization intended to transition this account from Cloud-Only to Hybrid. Verify the consistency between the on-premises 'ObjectGUID' and the newly assigned 'ImmutableID' in Azure AD.","investigative_actions": "Check if the cloud account was an administrator (Global Admin, etc.) before this sync. Determine if the on-premise user was recently created or if its 'proxyAddress' attribute was recently modified. Confirm if the organization intended to transition this account from Cloud-Only to Hybrid. Verify the consistency between the on-premises 'ObjectGUID' and the newly assigned 'ImmutableID' in Azure AD.","name": "First-time directory sync of an on-premises domain user to an existing cloud account","name": "First-time directory sync of an on-premises domain user to an existing cloud account","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "Attackers may leverage DirectorySync to move laterally from a compromised on-premise environment into the cloud tenant, allowing them to bypass the cloud's security boundaries and take over high-value cloud identities.", "deduplication_period": "1 Day", "description": "First-time synchronization of an on-premises domain user with an existing cloud account.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the cloud account was an administrator (Global Admin, etc.) before this sync. Determine if the on-premise user was recently created or if its 'proxyAddress' attribute was recently modified. Confirm if the organization intended to transition this account from Cloud-Only to Hybrid. Verify the consistency between the on-premises 'ObjectGUID' and the newly assigned 'ImmutableID' in Azure AD.", "name": "First-time directory sync of an on-premises domain user to an existing cloud account", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ GCP Logging Bucket Deletion modified +1 −1
analytics/gcp-logging-bucket-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection.","attackers_goals": "Evade detection.","deduplication_period": "3 Hours","deduplication_period": "3 Hours","description": "A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection.","description": "A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "Cloud Data Asset Disaster Recovery Risks, Data Detection & Response","detector_tags": "Cloud Data Asset Disaster Recovery Risks, Data Detection & Response, Cloud Log Tampering Analytics","investigative_actions": "Check which logs were affected by the bucket deletion. Check The cloud identity activity prior/after to the bucket deletion.","investigative_actions": "Check which logs were affected by the bucket deletion. Check The cloud identity activity prior/after to the bucket deletion.","name": "GCP Logging Bucket Deletion","name": "GCP Logging Bucket Deletion","required_data": ["required_data": ["Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection.", "deduplication_period": "3 Hours", "description": "A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection.", "detection_modules": "Cloud", - "detector_tags": "Cloud Data Asset Disaster Recovery Risks, Data Detection & Response", + "detector_tags": "Cloud Data Asset Disaster Recovery Risks, Data Detection & Response, Cloud Log Tampering Analytics", "investigative_actions": "Check which logs were affected by the bucket deletion. Check The cloud identity activity prior/after to the bucket deletion.", "name": "GCP Logging Bucket Deletion", "required_data": [ "Gcp Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ GCP logging sink deletion modified +1 −1
analytics/gcp-logging-sink-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection by limiting collected data.","attackers_goals": "Evade detection by limiting collected data.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection.","description": "A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Identify the logs impacted by the deletion. Review cloud identity activity before and after the deletion.","investigative_actions": "Identify the logs impacted by the deletion. Review cloud identity activity before and after the deletion.","name": "GCP logging sink deletion","name": "GCP logging sink deletion","required_data": ["required_data": ["Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection by limiting collected data.", "deduplication_period": "5 Days", "description": "A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Identify the logs impacted by the deletion. Review cloud identity activity before and after the deletion.", "name": "GCP logging sink deletion", "required_data": [ "Gcp Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ GCP logging sink modification modified +1 −1
analytics/gcp-logging-sink-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection by limiting collected data.","attackers_goals": "Evade detection by limiting collected data.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection.","description": "A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Identify the relevant logs impacted by the modification. Review The cloud identity activity before and after the logging sink modification.","investigative_actions": "Identify the relevant logs impacted by the modification. Review The cloud identity activity before and after the logging sink modification.","name": "GCP logging sink modification","name": "GCP logging sink modification","required_data": ["required_data": ["Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection by limiting collected data.", "deduplication_period": "5 Days", "description": "A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Identify the relevant logs impacted by the modification. Review The cloud identity activity before and after the logging sink modification.", "name": "GCP logging sink modification", "required_data": [ "Gcp Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ Gmail delegation was turned on for the organization modified +1 −1
analytics/gmail-delegation-was-turned-on-for-the-organizationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Domain or Tenant Policy Modification (T1484)""Domain or Tenant Policy Modification (T1484)"],],"attackers_goals": "Email Collection.","attackers_goals": "Email Collection.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A Google Workspace admin turned on Gmail delegation for all the organization's users.","description": "A Google Workspace admin turned on Gmail delegation for all the organization's users.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if any user in the organization granted other users access to their mail inbox. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if any user in the organization granted other users access to their mail inbox. Follow further actions done by the account.","name": "Gmail delegation was turned on for the organization","name": "Gmail delegation was turned on for the organization","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Domain or Tenant Policy Modification (T1484)" ], "attackers_goals": "Email Collection.", "deduplication_period": "5 Days", "description": "A Google Workspace admin turned on Gmail delegation for all the organization's users.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if any user in the organization granted other users access to their mail inbox. Follow further actions done by the account.", "name": "Gmail delegation was turned on for the organization", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)",