Analytics rules — August 23, 2026
166 files changed, 475 insertions, 179 deletions — view the commit on the mirror.
Four universal authentication detectors added; 124 identity detectors gain the SaaS Threat Detection module
- Four new Identity Analytics detectors cover a newly named event class, universal authentication: brute force, password spray, inactive-user authentication, and successful sign-in with suspicious features.
- 124 detectors were reassigned, adding
SaaS Threat DetectionalongsideIdentity Threat Module— 103 identity detectors and 21 that also carryEmail. - 36 cloud detectors gained a
detector_tagsgrouping for the first time: Cloud Log Tampering Analytics, OCI Analytics, and SSM Remote Management Analytics. - One rule was renamed, one variation was withdrawn, and two deduplication periods were retuned. Nothing else changed.
Highlights
-
Universal authentication arrives as its own detection surface
Four rules, all Identity Analytics with a 14-day activation period, hunt brute force and password spray over a 1-hour test period plus two single-event detections for inactive users and suspicious sign-in features.
-
124 detectors now name SaaS Threat Detection as a detection module
Every one of them kept Identity Threat Module and added SaaS Threat Detection next to it, so this widens which module each detector is listed under rather than moving any of them.
-
The Email module set was extended the same way
21 Exchange, DLP and mail-flow detectors went from `Identity Threat Module, Email` to `Identity Threat Module, SaaS Threat Detection, Email`.
-
Three new detector tag groupings appear across cloud detectors
19 detectors were tagged Cloud Log Tampering Analytics, 11 OCI Analytics, and 6 SSM Remote Management Analytics, in each case added to a previously empty or existing tag list.
-
The rare internal firewall vulnerability rule was renamed to name NGFW explicitly
"Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert" became "Analytics enhanced NGFW Threat Alert - …", changing the file path as well as the rule and variation names.
-
AWS SSM parameters retrieval lost a variation and deduplicates far more often
The Informational "Unusual AWS SSM parameters retrieval" variation was removed outright and does not reappear elsewhere, while the deduplication period dropped from 5 Days to 1 Day.
Changes
166 files listed, 7 written up and shaded below.
-
▸ ▾ Gmail routing settings changed modified +1 −1
analytics/gmail-routing-settings-changedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Data Staged (T1074)","Data Staged (T1074)","Email Collection (T1114)""Email Collection (T1114)"],],"attackers_goals": "Email Collection.","attackers_goals": "Email Collection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Gmail routing settings were modified.","description": "Gmail routing settings were modified.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new routing settings look suspicious. Investigate the IP address associated with the routing settings. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new routing settings look suspicious. Investigate the IP address associated with the routing settings. Follow further actions done by the account.","name": "Gmail routing settings changed","name": "Gmail routing settings changed","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Data Staged (T1074)", "Email Collection (T1114)" ], "attackers_goals": "Email Collection.", "deduplication_period": "1 Day", "description": "Gmail routing settings were modified.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new routing settings look suspicious. Investigate the IP address associated with the routing settings. Follow further actions done by the account.", "name": "Gmail routing settings changed", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Google Marketplace restrictions were modified modified +1 −1
analytics/google-marketplace-restrictions-were-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Domain or Tenant Policy Modification (T1484)""Domain or Tenant Policy Modification (T1484)"],],"attackers_goals": "Malicious Apps can be used to access the organization's Google data.","attackers_goals": "Malicious Apps can be used to access the organization's Google data.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "An identity modified Google Marketplace Restrictions.","description": "An identity modified Google Marketplace Restrictions.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.","name": "Google Marketplace restrictions were modified","name": "Google Marketplace restrictions were modified","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Domain or Tenant Policy Modification (T1484)" ], "attackers_goals": "Malicious Apps can be used to access the organization's Google data.", "deduplication_period": "2 Days", "description": "An identity modified Google Marketplace Restrictions.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.", "name": "Google Marketplace restrictions were modified", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Google Workspace automation was created modified +1 −1
analytics/google-workspace-automation-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@"attack_techniques": ["attack_techniques": ["Command and Scripting Interpreter (T1059)","Command and Scripting Interpreter (T1059)","Event Triggered Execution (T1546)","Event Triggered Execution (T1546)","Automated Exfiltration (T1020)""Automated Exfiltration (T1020)"],],"attackers_goals": "Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.","attackers_goals": "Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Google Workspace automation was created.","description": "Google Workspace automation was created.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Verify if the automation creation was authorized and expected for this user. Investigate the automation logic to determine if it is malicious. Investigate other suspicious activities performed by the user around the same timeframe.","investigative_actions": "Verify if the automation creation was authorized and expected for this user. Investigate the automation logic to determine if it is malicious. Investigate other suspicious activities performed by the user around the same timeframe.","name": "Google Workspace automation was created","name": "Google Workspace automation was created","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -8,17 +8,17 @@ "attack_techniques": [ "Command and Scripting Interpreter (T1059)", "Event Triggered Execution (T1546)", "Automated Exfiltration (T1020)" ], "attackers_goals": "Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.", "deduplication_period": "1 Day", "description": "Google Workspace automation was created.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Verify if the automation creation was authorized and expected for this user. Investigate the automation logic to determine if it is malicious. Investigate other suspicious activities performed by the user around the same timeframe.", "name": "Google Workspace automation was created", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Google Workspace organizational unit was modified modified +1 −1
analytics/google-workspace-organizational-unit-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation (T1098)""Account Manipulation (T1098)"],],"attackers_goals": "Adversaries may change the organizational unit the user belongs to, so they could inherit permissions for applications and resources that were inaccessible before.","attackers_goals": "Adversaries may change the organizational unit the user belongs to, so they could inherit permissions for applications and resources that were inaccessible before.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A Google Workspace admin modified an organizational unit.","description": "A Google Workspace admin modified an organizational unit.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account.","name": "Google Workspace organizational unit was modified","name": "Google Workspace organizational unit was modified","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Account Manipulation (T1098)" ], "attackers_goals": "Adversaries may change the organizational unit the user belongs to, so they could inherit permissions for applications and resources that were inaccessible before.", "deduplication_period": "5 Days", "description": "A Google Workspace admin modified an organizational unit.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account.", "name": "Google Workspace organizational unit was modified", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Google Workspace third-party application's security settings were changed modified +1 −1
analytics/google-workspace-third-party-application-s-security-settings-were-changedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Domain or Tenant Policy Modification (T1484)""Domain or Tenant Policy Modification (T1484)"],],"attackers_goals": "Malicious apps can be used to access the organization's Google data.","attackers_goals": "Malicious apps can be used to access the organization's Google data.","deduplication_period": "2 Days","deduplication_period": "2 Days","description": "An identity changed Google Workspace third-party application's security settings.","description": "An identity changed Google Workspace third-party application's security settings.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.","investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.","name": "Google Workspace third-party application's security settings were changed","name": "Google Workspace third-party application's security settings were changed","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Domain or Tenant Policy Modification (T1484)" ], "attackers_goals": "Malicious apps can be used to access the organization's Google data.", "deduplication_period": "2 Days", "description": "An identity changed Google Workspace third-party application's security settings.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.", "name": "Google Workspace third-party application's security settings were changed", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Google Workspace user authentication information changed modified +1 −1
analytics/google-workspace-user-authentication-information-changedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Modify Authentication Process: Multi-Factor Authentication (T1556.006)","Modify Authentication Process: Multi-Factor Authentication (T1556.006)","Account Manipulation (T1098)""Account Manipulation (T1098)"],],"attackers_goals": "Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.","attackers_goals": "Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Google Workspace authentication information was changed for a user.","description": "Google Workspace authentication information was changed for a user.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Verify if the authentication information change was authorized. Follow further actions done by the user and IP address.","investigative_actions": "Verify if the authentication information change was authorized. Follow further actions done by the user and IP address.","name": "Google Workspace user authentication information changed","name": "Google Workspace user authentication information changed","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Modify Authentication Process: Multi-Factor Authentication (T1556.006)", "Account Manipulation (T1098)" ], "attackers_goals": "Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.", "deduplication_period": "1 Day", "description": "Google Workspace authentication information was changed for a user.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Verify if the authentication information change was authorized. Follow further actions done by the user and IP address.", "name": "Google Workspace user authentication information changed", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Identity assigned an Azure AD Administrator Role modified +1 −1
analytics/identity-assigned-an-azure-ad-administrator-roleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation: Additional Cloud Roles (T1098.003)""Account Manipulation: Additional Cloud Roles (T1098.003)"],],"attackers_goals": "An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.","attackers_goals": "An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity was assigned an Azure AD Administrator role.","description": "An identity was assigned an Azure AD Administrator role.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the added account is new to the organization. Check whether the account that added the account to the role is permitted to perform such actions. Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.","investigative_actions": "Check if the added account is new to the organization. Check whether the account that added the account to the role is permitted to perform such actions. Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.","name": "Identity assigned an Azure AD Administrator Role","name": "Identity assigned an Azure AD Administrator Role","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Account Manipulation: Additional Cloud Roles (T1098.003)" ], "attackers_goals": "An attacker may add additional roles or permissions to an attacker controlled cloud account to maintain persistent access to a tenant.", "deduplication_period": "1 Day", "description": "An identity was assigned an Azure AD Administrator role.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the added account is new to the organization. Check whether the account that added the account to the role is permitted to perform such actions. Check what can be affected by the assigned role* Follow further actions done by the account that was added to the role.", "name": "Identity assigned an Azure AD Administrator Role", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Impossible travel by a cloud identity modified +1 −1
analytics/impossible-travel-by-a-cloud-identityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Valid Accounts: Cloud Accounts (T1078.004)""Valid Accounts: Cloud Accounts (T1078.004)"],],"attackers_goals": "Obtain and abuse credentials of cloud accounts.","attackers_goals": "Obtain and abuse credentials of cloud accounts.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account.","description": "Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Verify if the identity's credentials have been compromised. Examine the recent activity of the identity in question.","investigative_actions": "Verify if the identity's credentials have been compromised. Examine the recent activity of the identity in question.","name": "Impossible travel by a cloud identity","name": "Impossible travel by a cloud identity","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Valid Accounts: Cloud Accounts (T1078.004)" ], "attackers_goals": "Obtain and abuse credentials of cloud accounts.", "deduplication_period": "5 Days", "description": "Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Verify if the identity's credentials have been compromised. Examine the recent activity of the identity in question.", "name": "Impossible travel by a cloud identity", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "Informational", -
▸ ▾ Increase in Job-Related Site Visits modified +1 −1
analytics/increase-in-job-related-site-visitsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Reconnaissance (TA0043)""Reconnaissance (TA0043)"],],"attack_techniques": ["attack_techniques": ["Search Open Websites/Domains (T1593)""Search Open Websites/Domains (T1593)"],],"attackers_goals": "This may be an early indicator of an insider threat.","attackers_goals": "This may be an early indicator of an insider threat.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user has visited multiple job-related sites in the past day.","description": "A user has visited multiple job-related sites in the past day.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Investigate the domains accessed and how popular they are in the organization. Check how long the user has been part of the organization. Verify that the user is not part of a department that accesses job sites as part of daily operations.","investigative_actions": "Investigate the domains accessed and how popular they are in the organization. Check how long the user has been part of the organization. Verify that the user is not part of a department that accesses job sites as part of daily operations.","name": "Increase in Job-Related Site Visits","name": "Increase in Job-Related Site Visits","required_data": ["required_data": ["Palo Alto Networks Firewall EAL Logs","Palo Alto Networks Firewall EAL Logs","Palo Alto Networks Firewall threat Logs","Palo Alto Networks Firewall threat Logs","Palo Alto Networks Firewall EAL Logs","Palo Alto Networks Firewall EAL Logs","XDR Agent""XDR Agent"Show markdown source
@@ -4,17 +4,17 @@ "Reconnaissance (TA0043)" ], "attack_techniques": [ "Search Open Websites/Domains (T1593)" ], "attackers_goals": "This may be an early indicator of an insider threat.", "deduplication_period": "1 Day", "description": "A user has visited multiple job-related sites in the past day.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Investigate the domains accessed and how popular they are in the organization. Check how long the user has been part of the organization. Verify that the user is not part of a department that accesses job sites as part of daily operations.", "name": "Increase in Job-Related Site Visits", "required_data": [ "Palo Alto Networks Firewall EAL Logs", "Palo Alto Networks Firewall threat Logs", "Palo Alto Networks Firewall EAL Logs", "XDR Agent" -
▸ ▾ Invalid SAML Detected modified +1 −1
analytics/invalid-saml-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Credential Access (TA0006)""Credential Access (TA0006)"],],"attack_techniques": ["attack_techniques": ["Forge Web Credentials: SAML Tokens (T1606.002)""Forge Web Credentials: SAML Tokens (T1606.002)"],],"attackers_goals": "An attacker might forge a valid SAML token to impersonate other user accounts. This is used to gain persistent, unauthorized access to cloud resources, and bypassing MFA.","attackers_goals": "An attacker might forge a valid SAML token to impersonate other user accounts. This is used to gain persistent, unauthorized access to cloud resources, and bypassing MFA.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack.","description": "A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Active Directory Federation Services Analytics","detector_tags": "Active Directory Federation Services Analytics","investigative_actions": "Check for recent changes to the SAML signing certificate on both the Identity Provider and the Service Provider to rule out a configuration drift or expiration issue. Check for other correlated alerts on on-premises systems that may be related to the Golden SAML attack. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).","investigative_actions": "Check for recent changes to the SAML signing certificate on both the Identity Provider and the Service Provider to rule out a configuration drift or expiration issue. Check for other correlated alerts on on-premises systems that may be related to the Golden SAML attack. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).","name": "Invalid SAML Detected","name": "Invalid SAML Detected","required_data": ["required_data": ["AzureAD","AzureAD","Okta""Okta"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -4,17 +4,17 @@ "Credential Access (TA0006)" ], "attack_techniques": [ "Forge Web Credentials: SAML Tokens (T1606.002)" ], "attackers_goals": "An attacker might forge a valid SAML token to impersonate other user accounts. This is used to gain persistent, unauthorized access to cloud resources, and bypassing MFA.", "deduplication_period": "1 Day", "description": "A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Active Directory Federation Services Analytics", "investigative_actions": "Check for recent changes to the SAML signing certificate on both the Identity Provider and the Service Provider to rule out a configuration drift or expiration issue. Check for other correlated alerts on on-premises systems that may be related to the Golden SAML attack. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).", "name": "Invalid SAML Detected", "required_data": [ "AzureAD", "Okta" ], "severity": "Informational", -
▸ ▾ Large volume of files potentially containing credentials accessed in Google Drive modified +1 −1
analytics/large-volume-of-files-potentially-containing-credentials-accessed-in-google-driveRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Data from Cloud Storage (T1530)","Data from Cloud Storage (T1530)","Unsecured Credentials (T1552)""Unsecured Credentials (T1552)"],],"attackers_goals": "An attacker may attempt to gain unauthorized access by leveraging valid credentials found in Google Drive.","attackers_goals": "An attacker may attempt to gain unauthorized access by leveraging valid credentials found in Google Drive.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user accessed a large volume of files potentially containing credentials in Google Drive.","description": "A user accessed a large volume of files potentially containing credentials in Google Drive.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace, Data Detection & Response","detector_tags": "Google Workspace, Data Detection & Response","investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Verify if the user account that accessed the files is authorized to access them. Review the files accessed and whether it was part of a breach or a legitimate activity. Monitor the account for any further suspicious actions.","investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Verify if the user account that accessed the files is authorized to access them. Review the files accessed and whether it was part of a breach or a legitimate activity. Monitor the account for any further suspicious actions.","name": "Large volume of files potentially containing credentials accessed in Google Drive","name": "Large volume of files potentially containing credentials accessed in Google Drive","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Data from Cloud Storage (T1530)", "Unsecured Credentials (T1552)" ], "attackers_goals": "An attacker may attempt to gain unauthorized access by leveraging valid credentials found in Google Drive.", "deduplication_period": "1 Day", "description": "A user accessed a large volume of files potentially containing credentials in Google Drive.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace, Data Detection & Response", "investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Verify if the user account that accessed the files is authorized to access them. Review the files accessed and whether it was part of a breach or a legitimate activity. Monitor the account for any further suspicious actions.", "name": "Large volume of files potentially containing credentials accessed in Google Drive", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ Logging was impaired via external encryption key modified +1 −1
analytics/logging-was-impaired-via-external-encryption-keyRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Data Manipulation (T1565)","Data Manipulation (T1565)","Impair Defenses (T1562)""Impair Defenses (T1562)"],],"attackers_goals": "Modifying the key used to encrypt the logs to remain undetected.","attackers_goals": "Modifying the key used to encrypt the logs to remain undetected.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "The resource was configured with an external key This might be an attempt to disrupt log inspection.","description": "The resource was configured with an external key This might be an attempt to disrupt log inspection.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Check the identity that updated the resource configuration. Check the key used to encrypt the logs.","investigative_actions": "Check the identity that updated the resource configuration. Check the key used to encrypt the logs.","name": "Logging was impaired via external encryption key","name": "Logging was impaired via external encryption key","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Medium","severity": "Medium","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Data Manipulation (T1565)", "Impair Defenses (T1562)" ], "attackers_goals": "Modifying the key used to encrypt the logs to remain undetected.", "deduplication_period": "1 Day", "description": "The resource was configured with an external key This might be an attempt to disrupt log inspection.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Check the identity that updated the resource configuration. Check the key used to encrypt the logs.", "name": "Logging was impaired via external encryption key", "required_data": [ "AWS Audit Log", "Gcp Audit Log" ], "severity": "Medium", "test_period": "N/A (single event)", -
▸ ▾ Massive file downloads from SaaS service modified +1 −1
analytics/massive-file-downloads-from-saas-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Collection (TA0009)""Collection (TA0009)"],],"attack_techniques": ["attack_techniques": ["Data from Cloud Storage (T1530)""Data from Cloud Storage (T1530)"],],"attackers_goals": "An attacker may download files from a SaaS service to exfiltrate sensitive data.","attackers_goals": "An attacker may download files from a SaaS service to exfiltrate sensitive data.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior.","description": "A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "Data Detection & Response","detector_tags": "Data Detection & Response","investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Review the files that were downloaded to determine if they contain sensitive data. Verify if the user account that downloaded the files is authorized to access them. Analyze the file types that were downloaded. Monitor the account for any further suspicious actions.","investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Review the files that were downloaded to determine if they contain sensitive data. Verify if the user account that downloaded the files is authorized to access them. Analyze the file types that were downloaded. Monitor the account for any further suspicious actions.","name": "Massive file downloads from SaaS service","name": "Massive file downloads from SaaS service","required_data": ["required_data": ["Box Audit Log","Box Audit Log","DropBox","DropBox","Google Workspace Audit Logs","Google Workspace Audit Logs","Office 365 Audit""Office 365 Audit"Show markdown source
@@ -4,17 +4,17 @@ "Collection (TA0009)" ], "attack_techniques": [ "Data from Cloud Storage (T1530)" ], "attackers_goals": "An attacker may download files from a SaaS service to exfiltrate sensitive data.", "deduplication_period": "1 Day", "description": "A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "Data Detection & Response", "investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Review the files that were downloaded to determine if they contain sensitive data. Verify if the user account that downloaded the files is authorized to access them. Analyze the file types that were downloaded. Monitor the account for any further suspicious actions.", "name": "Massive file downloads from SaaS service", "required_data": [ "Box Audit Log", "DropBox", "Google Workspace Audit Logs", "Office 365 Audit" -
▸ ▾ Massive upload to a rare storage or mail domain modified +1 −1
analytics/massive-upload-to-a-rare-storage-or-mail-domainRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Exfiltration Over Web Service (T1567)","Exfiltration Over Web Service (T1567)","Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)""Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)"],],"attackers_goals": "A user uploaded an abnormal amount of data to a file sharing service. This activity might indicate an attempt to exfiltrate files and data from the organization.","attackers_goals": "A user uploaded an abnormal amount of data to a file sharing service. This activity might indicate an attempt to exfiltrate files and data from the organization.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration.","description": "A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Data Detection & Response","detector_tags": "Data Detection & Response","investigative_actions": "Check for any other suspicious activity related to the host and the user involved in the alert. Identify the user uploading the data to determine if the transfer is sanctioned.","investigative_actions": "Check for any other suspicious activity related to the host and the user involved in the alert. Identify the user uploading the data to determine if the transfer is sanctioned.","name": "Massive upload to a rare storage or mail domain","name": "Massive upload to a rare storage or mail domain","required_data": ["required_data": ["Palo Alto Networks Firewall EAL Logs","Palo Alto Networks Firewall EAL Logs","Palo Alto Networks Firewall threat Logs","Palo Alto Networks Firewall threat Logs","XDR Agent""XDR Agent"],],Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Exfiltration Over Web Service (T1567)", "Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)" ], "attackers_goals": "A user uploaded an abnormal amount of data to a file sharing service. This activity might indicate an attempt to exfiltrate files and data from the organization.", "deduplication_period": "1 Day", "description": "A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Data Detection & Response", "investigative_actions": "Check for any other suspicious activity related to the host and the user involved in the alert. Identify the user uploading the data to determine if the transfer is sanctioned.", "name": "Massive upload to a rare storage or mail domain", "required_data": [ "Palo Alto Networks Firewall EAL Logs", "Palo Alto Networks Firewall threat Logs", "XDR Agent" ], -
▸ ▾ Massive upload to SaaS service modified +1 −1
analytics/massive-upload-to-saas-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Exfiltration Over Web Service (T1567)","Exfiltration Over Web Service (T1567)","Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)","Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)","Data Staged: Remote Data Staging (T1074.002)""Data Staged: Remote Data Staging (T1074.002)"],],"attackers_goals": "An attacker may upload files to a SaaS service to stage and exfiltrate data from the organization.","attackers_goals": "An attacker may upload files to a SaaS service to stage and exfiltrate data from the organization.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged.","description": "A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Data Detection & Response","detector_tags": "Data Detection & Response","investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Review the files that were uploaded to determine if they contain sensitive data. Verify if the user account that uploaded the files is authorized to access them. Analyze the file types that were uploaded. Monitor the account for any further suspicious actions.","investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Review the files that were uploaded to determine if they contain sensitive data. Verify if the user account that uploaded the files is authorized to access them. Analyze the file types that were uploaded. Monitor the account for any further suspicious actions.","name": "Massive upload to SaaS service","name": "Massive upload to SaaS service","required_data": ["required_data": ["Box Audit Log","Box Audit Log","DropBox","DropBox","Google Workspace Audit Logs","Google Workspace Audit Logs","Office 365 Audit""Office 365 Audit"Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Exfiltration Over Web Service (T1567)", "Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)", "Data Staged: Remote Data Staging (T1074.002)" ], "attackers_goals": "An attacker may upload files to a SaaS service to stage and exfiltrate data from the organization.", "deduplication_period": "1 Day", "description": "A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Data Detection & Response", "investigative_actions": "Check for signs of account compromise, such as abnormal login activity or unusual behavior. Review the files that were uploaded to determine if they contain sensitive data. Verify if the user account that uploaded the files is authorized to access them. Analyze the file types that were uploaded. Monitor the account for any further suspicious actions.", "name": "Massive upload to SaaS service", "required_data": [ "Box Audit Log", "DropBox", "Google Workspace Audit Logs", "Office 365 Audit" -
▸ ▾ MFA Disabled for Google Workspace modified +1 −1
analytics/mfa-disabled-for-google-workspaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Modify Authentication Process (T1556)","Modify Authentication Process (T1556)","Modify Authentication Process: Multi-Factor Authentication (T1556.006)""Modify Authentication Process: Multi-Factor Authentication (T1556.006)"],],"attackers_goals": "Gain access to Google Workspace accounts with disabled MFA. Exploit Google Workspace accounts with weaker security. Steal sensitive data from Google Workspace accounts.","attackers_goals": "Gain access to Google Workspace accounts with disabled MFA. Exploit Google Workspace accounts with weaker security. Steal sensitive data from Google Workspace accounts.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An administrator has disabled Multi-Factor Authentication for Google Workspace users.","description": "An administrator has disabled Multi-Factor Authentication for Google Workspace users.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Check the MFA settings for the Google Workspace users. Identify the users who have MFA disabled and investigate the reason for it. Check the security log to see if there have been any suspicious activities in the account.","investigative_actions": "Check the MFA settings for the Google Workspace users. Identify the users who have MFA disabled and investigate the reason for it. Check the security log to see if there have been any suspicious activities in the account.","name": "MFA Disabled for Google Workspace","name": "MFA Disabled for Google Workspace","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Modify Authentication Process (T1556)", "Modify Authentication Process: Multi-Factor Authentication (T1556.006)" ], "attackers_goals": "Gain access to Google Workspace accounts with disabled MFA. Exploit Google Workspace accounts with weaker security. Steal sensitive data from Google Workspace accounts.", "deduplication_period": "5 Days", "description": "An administrator has disabled Multi-Factor Authentication for Google Workspace users.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Check the MFA settings for the Google Workspace users. Identify the users who have MFA disabled and investigate the reason for it. Check the security log to see if there have been any suspicious activities in the account.", "name": "MFA Disabled for Google Workspace", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ MFA was disabled for a Google Workspace user modified +1 −1
analytics/mfa-was-disabled-for-a-google-workspace-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Modify Authentication Process: Multi-Factor Authentication (T1556.006)""Modify Authentication Process: Multi-Factor Authentication (T1556.006)"],],"attackers_goals": "Adversaries may impair defenses by disabling Multi-Factor Authentication (MFA) to maintain persistence and evade detection.","attackers_goals": "Adversaries may impair defenses by disabling Multi-Factor Authentication (MFA) to maintain persistence and evade detection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user.","description": "Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Verify if the MFA disablement was authorized. Investigate the source IP and User Agent for previous malicious activity or anomalies. Follow further actions done by the user and IP address.","investigative_actions": "Verify if the MFA disablement was authorized. Investigate the source IP and User Agent for previous malicious activity or anomalies. Follow further actions done by the user and IP address.","name": "MFA was disabled for a Google Workspace user","name": "MFA was disabled for a Google Workspace user","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Modify Authentication Process: Multi-Factor Authentication (T1556.006)" ], "attackers_goals": "Adversaries may impair defenses by disabling Multi-Factor Authentication (MFA) to maintain persistence and evade detection.", "deduplication_period": "1 Day", "description": "Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Verify if the MFA disablement was authorized. Investigate the source IP and User Agent for previous malicious activity or anomalies. Follow further actions done by the user and IP address.", "name": "MFA was disabled for a Google Workspace user", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ MFA was disabled for an Azure identity modified +1 −1
analytics/mfa-was-disabled-for-an-azure-identityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Modify Authentication Process (T1556)""Modify Authentication Process (T1556)"],],"attackers_goals": "This allows the attacker to connect using this account without the need for the additional layer of authentication.","attackers_goals": "This allows the attacker to connect using this account without the need for the additional layer of authentication.","deduplication_period": "1 Hour","deduplication_period": "1 Hour","description": "MFA was disabled for the user.","description": "MFA was disabled for the user.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions by the initiator. Check the login activity from this account. Follow further actions done by this account.","investigative_actions": "Follow further actions by the initiator. Check the login activity from this account. Follow further actions done by this account.","name": "MFA was disabled for an Azure identity","name": "MFA was disabled for an Azure identity","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Modify Authentication Process (T1556)" ], "attackers_goals": "This allows the attacker to connect using this account without the need for the additional layer of authentication.", "deduplication_period": "1 Hour", "description": "MFA was disabled for the user.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Follow further actions by the initiator. Check the login activity from this account. Follow further actions done by this account.", "name": "MFA was disabled for an Azure identity", "required_data": [ "AzureAD Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Microsoft 365 DLP policy disabled or removed modified +1 −1
analytics/microsoft-365-dlp-policy-disabled-or-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Tools (T1562.001)""Impair Defenses: Disable or Modify Tools (T1562.001)"],],"attackers_goals": "An attacker is attempting to bypass Microsoft 365 Data Loss Prevention (DLP) policies.","attackers_goals": "An attacker is attempting to bypass Microsoft 365 Data Loss Prevention (DLP) policies.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion.","description": "A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Monitor the user's activity for any access to sensitive data or data exfiltration. Investigate if any other security policies have been changed or removed.","investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Monitor the user's activity for any access to sensitive data or data exfiltration. Investigate if any other security policies have been changed or removed.","name": "Microsoft 365 DLP policy disabled or removed","name": "Microsoft 365 DLP policy disabled or removed","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Tools (T1562.001)" ], "attackers_goals": "An attacker is attempting to bypass Microsoft 365 Data Loss Prevention (DLP) policies.", "deduplication_period": "1 Day", "description": "A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Monitor the user's activity for any access to sensitive data or data exfiltration. Investigate if any other security policies have been changed or removed.", "name": "Microsoft 365 DLP policy disabled or removed", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Microsoft Teams application setup policy was modified modified +1 −1
analytics/microsoft-teams-application-setup-policy-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Cloud Application Integration (T1671)""Cloud Application Integration (T1671)"],],"attackers_goals": "Attackers may modify the application setup policy to maintain persistent access to compromised Teams accounts and conversations.","attackers_goals": "Attackers may modify the application setup policy to maintain persistent access to compromised Teams accounts and conversations.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Microsoft Teams the application setup policy, which is responsible for application management, was modified.","description": "Microsoft Teams the application setup policy, which is responsible for application management, was modified.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Determine if it is within the user's role to modify the policy. Verify whether the modification of the policy is both legitimate and necessary. If the policy change causes an application installed for the whole organization, confirm that the application was created by a certified and trusted entity. Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID or the unique token identifier.","investigative_actions": "Determine if it is within the user's role to modify the policy. Verify whether the modification of the policy is both legitimate and necessary. If the policy change causes an application installed for the whole organization, confirm that the application was created by a certified and trusted entity. Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID or the unique token identifier.","name": "Microsoft Teams application setup policy was modified","name": "Microsoft Teams application setup policy was modified","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Cloud Application Integration (T1671)" ], "attackers_goals": "Attackers may modify the application setup policy to maintain persistent access to compromised Teams accounts and conversations.", "deduplication_period": "1 Day", "description": "Microsoft Teams the application setup policy, which is responsible for application management, was modified.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Determine if it is within the user's role to modify the policy. Verify whether the modification of the policy is both legitimate and necessary. If the policy change causes an application installed for the whole organization, confirm that the application was created by a certified and trusted entity. Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID or the unique token identifier.", "name": "Microsoft Teams application setup policy was modified", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Microsoft Teams external communication policy was modified modified +1 −1
analytics/microsoft-teams-external-communication-policy-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Exfiltration Over Alternative Protocol (T1048)""Exfiltration Over Alternative Protocol (T1048)"],],"attackers_goals": "Attackers may modify the external communication policy to enable data exfiltration or to hide their activities.","attackers_goals": "Attackers may modify the external communication policy to enable data exfiltration or to hide their activities.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Microsoft Teams external communication policy was modified.","description": "Microsoft Teams external communication policy was modified.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Determine if it is within the user's role to modify the policy. Verify whether the modification of the policy is both legitimate and necessary. Follow further communication with the external tenant or allowed tenants. Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID.","investigative_actions": "Determine if it is within the user's role to modify the policy. Verify whether the modification of the policy is both legitimate and necessary. Follow further communication with the external tenant or allowed tenants. Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID.","name": "Microsoft Teams external communication policy was modified","name": "Microsoft Teams external communication policy was modified","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Impair Defenses (T1562)", "Exfiltration Over Alternative Protocol (T1048)" ], "attackers_goals": "Attackers may modify the external communication policy to enable data exfiltration or to hide their activities.", "deduplication_period": "1 Day", "description": "Microsoft Teams external communication policy was modified.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Determine if it is within the user's role to modify the policy. Verify whether the modification of the policy is both legitimate and necessary. Follow further communication with the external tenant or allowed tenants. Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID.", "name": "Microsoft Teams external communication policy was modified", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Microsoft Teams messages were exported from conversation modified +1 −1
analytics/microsoft-teams-messages-were-exported-from-conversationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Collection (TA0009)""Collection (TA0009)"],],"attack_techniques": ["attack_techniques": ["Data from Information Repositories: Messaging Applications (T1213.005)""Data from Information Repositories: Messaging Applications (T1213.005)"],],"attackers_goals": "Attackers may leverage message extraction from Microsoft Teams to obtain valuable information.","attackers_goals": "Attackers may leverage message extraction from Microsoft Teams to obtain valuable information.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Microsoft Teams messages were exported from conversation.","description": "Microsoft Teams messages were exported from conversation.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.","investigative_actions": "Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.","name": "Microsoft Teams messages were exported from conversation","name": "Microsoft Teams messages were exported from conversation","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Collection (TA0009)" ], "attack_techniques": [ "Data from Information Repositories: Messaging Applications (T1213.005)" ], "attackers_goals": "Attackers may leverage message extraction from Microsoft Teams to obtain valuable information.", "deduplication_period": "1 Day", "description": "Microsoft Teams messages were exported from conversation.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.", "name": "Microsoft Teams messages were exported from conversation", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Multiple Azure AD admin role removals modified +1 −1
analytics/multiple-azure-ad-admin-role-removalsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Impact (TA0040)""Impact (TA0040)"],],"attack_techniques": ["attack_techniques": ["Account Access Removal (T1531)""Account Access Removal (T1531)"],],"attackers_goals": "An attacker may want to lock out an organization and retain sole access.","attackers_goals": "An attacker may want to lock out an organization and retain sole access.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An Azure AD identity removed multiple administrators from their roles.","description": "An Azure AD identity removed multiple administrators from their roles.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the identity performing the actions was authorized to perform them. Check what roles the users were removed from. Check whether the identity is a newly added admin. Check if the identity is operating in its usual manner (location, time, operations)* Check if the identity performed additional operations in the cloud environment that might be malicious.","investigative_actions": "Check if the identity performing the actions was authorized to perform them. Check what roles the users were removed from. Check whether the identity is a newly added admin. Check if the identity is operating in its usual manner (location, time, operations)* Check if the identity performed additional operations in the cloud environment that might be malicious.","name": "Multiple Azure AD admin role removals","name": "Multiple Azure AD admin role removals","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Low","severity": "Low","test_period": "3 Hours","test_period": "3 Hours",Show markdown source
@@ -4,17 +4,17 @@ "Impact (TA0040)" ], "attack_techniques": [ "Account Access Removal (T1531)" ], "attackers_goals": "An attacker may want to lock out an organization and retain sole access.", "deduplication_period": "1 Day", "description": "An Azure AD identity removed multiple administrators from their roles.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the identity performing the actions was authorized to perform them. Check what roles the users were removed from. Check whether the identity is a newly added admin. Check if the identity is operating in its usual manner (location, time, operations)* Check if the identity performed additional operations in the cloud environment that might be malicious.", "name": "Multiple Azure AD admin role removals", "required_data": [ "AzureAD Audit Log" ], "severity": "Low", "test_period": "3 Hours", -
▸ ▾ Multiple risk indicators for a cloud identity modified +1 −1
analytics/multiple-risk-indicators-for-a-cloud-identityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)","Valid Accounts (T1078)","Valid Accounts: Cloud Accounts (T1078.004)""Valid Accounts: Cloud Accounts (T1078.004)"],],"attackers_goals": "Compromise a cloud user account to gain access and perform malicious activities.","attackers_goals": "Compromise a cloud user account to gain access and perform malicious activities.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP.","description": "Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Review the user's recent activity for any unauthorized actions. Rotate the user's credentials immediately if confirmed compromised.","investigative_actions": "Review the user's recent activity for any unauthorized actions. Rotate the user's credentials immediately if confirmed compromised.","name": "Multiple risk indicators for a cloud identity","name": "Multiple risk indicators for a cloud identity","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "High","severity": "High",Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Valid Accounts (T1078)", "Valid Accounts: Cloud Accounts (T1078.004)" ], "attackers_goals": "Compromise a cloud user account to gain access and perform malicious activities.", "deduplication_period": "1 Day", "description": "Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Review the user's recent activity for any unauthorized actions. Rotate the user's credentials immediately if confirmed compromised.", "name": "Multiple risk indicators for a cloud identity", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "High", -
▸ ▾ New Teams application published to the organization catalog modified +1 −1
analytics/new-teams-application-published-to-the-organization-catalogRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation (T1098)""Account Manipulation (T1098)"],],"attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.","attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A new Teams application was published to the organization catalog.","description": "A new Teams application was published to the organization catalog.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the application was created by a certified and trusted entity. Evaluate the permissions requested by the application to determine if they are excessive or unusual. Determine if it is within the user's role to publish this type of application. Correlate the alert with the sign-in event to get additional information on the identity performing the action. Follow further actions done by the account.","investigative_actions": "Confirm that the application was created by a certified and trusted entity. Evaluate the permissions requested by the application to determine if they are excessive or unusual. Determine if it is within the user's role to publish this type of application. Correlate the alert with the sign-in event to get additional information on the identity performing the action. Follow further actions done by the account.","name": "New Teams application published to the organization catalog","name": "New Teams application published to the organization catalog","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Account Manipulation (T1098)" ], "attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.", "deduplication_period": "1 Day", "description": "A new Teams application was published to the organization catalog.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the application was created by a certified and trusted entity. Evaluate the permissions requested by the application to determine if they are excessive or unusual. Determine if it is within the user's role to publish this type of application. Correlate the alert with the sign-in event to get additional information on the identity performing the action. Follow further actions done by the account.", "name": "New Teams application published to the organization catalog", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Okta account reset password attempt modified +1 −1
analytics/okta-account-reset-password-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "The attacker might deceive the victim into resetting their password, a common tactic in account takeover schemes.","attackers_goals": "The attacker might deceive the victim into resetting their password, a common tactic in account takeover schemes.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user used a weak factor to reset their Okta password.","description": "A user used a weak factor to reset their Okta password.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Reach out to the user to confirm the legitimacy of the recent password reset activity. Examine the IP address and assess its reputation. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.","investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Reach out to the user to confirm the legitimacy of the recent password reset activity. Examine the IP address and assess its reputation. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.","name": "Okta account reset password attempt","name": "Okta account reset password attempt","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "The attacker might deceive the victim into resetting their password, a common tactic in account takeover schemes.", "deduplication_period": "1 Day", "description": "A user used a weak factor to reset their Okta password.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Reach out to the user to confirm the legitimacy of the recent password reset activity. Examine the IP address and assess its reputation. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.", "name": "Okta account reset password attempt", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ Okta account unlock by admin modified +1 −1
analytics/okta-account-unlock-by-adminRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "The attacker's goal is to gain unauthorized access to sensitive information or resources and to gain control over the locked account.","attackers_goals": "The attacker's goal is to gain unauthorized access to sensitive information or resources and to gain control over the locked account.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An administrative user unlocked an Okta account.","description": "An administrative user unlocked an Okta account.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Investigate abnormal logins, reported suspicious activities, new processes run, and recent configuration changes for any indicators of potential compromise. Examine the user's actions preceding and following the activation of the alert. Initiate contact with the user to verify the authenticity of the account unlock action. Check account the user successfully authenticated after the event. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.","investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Investigate abnormal logins, reported suspicious activities, new processes run, and recent configuration changes for any indicators of potential compromise. Examine the user's actions preceding and following the activation of the alert. Initiate contact with the user to verify the authenticity of the account unlock action. Check account the user successfully authenticated after the event. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.","name": "Okta account unlock by admin","name": "Okta account unlock by admin","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "The attacker's goal is to gain unauthorized access to sensitive information or resources and to gain control over the locked account.", "deduplication_period": "1 Day", "description": "An administrative user unlocked an Okta account.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Investigate abnormal logins, reported suspicious activities, new processes run, and recent configuration changes for any indicators of potential compromise. Examine the user's actions preceding and following the activation of the alert. Initiate contact with the user to verify the authenticity of the account unlock action. Check account the user successfully authenticated after the event. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.", "name": "Okta account unlock by admin", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Okta account unlock modified +1 −1
analytics/okta-account-unlockRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "The attacker's goal is to gain unauthorized access to sensitive information or resources and to gain control over the locked account.","attackers_goals": "The attacker's goal is to gain unauthorized access to sensitive information or resources and to gain control over the locked account.","deduplication_period": "3 Hours","deduplication_period": "3 Hours","description": "Okta user account was unlocked.","description": "Okta user account was unlocked.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Examine the user's actions preceding and following the activation of the alert. Initiate contact with the user to verify the authenticity of the account unlock action. Check account the user successfully authenticated after the event. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.","investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Examine the user's actions preceding and following the activation of the alert. Initiate contact with the user to verify the authenticity of the account unlock action. Check account the user successfully authenticated after the event. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.","name": "Okta account unlock","name": "Okta account unlock","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "The attacker's goal is to gain unauthorized access to sensitive information or resources and to gain control over the locked account.", "deduplication_period": "3 Hours", "description": "Okta user account was unlocked.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Examine the user's actions preceding and following the activation of the alert. Initiate contact with the user to verify the authenticity of the account unlock action. Check account the user successfully authenticated after the event. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.", "name": "Okta account unlock", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ Okta admin privilege assignment modified +1 −1
analytics/okta-admin-privilege-assignmentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Privilege Escalation (TA0004)""Privilege Escalation (TA0004)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation: Additional Cloud Credentials (T1098.001)""Account Manipulation: Additional Cloud Credentials (T1098.001)"],],"attackers_goals": "An attacker is attempting to gain access to sensitive information or systems, while privilege escalation involves their attempt to increase control and access within the system or network.","attackers_goals": "An attacker is attempting to gain access to sensitive information or systems, while privilege escalation involves their attempt to increase control and access within the system or network.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user assigned admin privileges to a new user or group.","description": "A user assigned admin privileges to a new user or group.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Analyze the actions carried out by the user responsible for granting permission.","investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Analyze the actions carried out by the user responsible for granting permission.","name": "Okta admin privilege assignment","name": "Okta admin privilege assignment","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Privilege Escalation (TA0004)" ], "attack_techniques": [ "Account Manipulation: Additional Cloud Credentials (T1098.001)" ], "attackers_goals": "An attacker is attempting to gain access to sensitive information or systems, while privilege escalation involves their attempt to increase control and access within the system or network.", "deduplication_period": "1 Day", "description": "A user assigned admin privileges to a new user or group.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Analyze the actions carried out by the user responsible for granting permission.", "name": "Okta admin privilege assignment", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Okta API Token Created modified +1 −1
analytics/okta-api-token-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@"attack_techniques": ["attack_techniques": ["Access Token Manipulation: Make and Impersonate Token (T1134.003)","Access Token Manipulation: Make and Impersonate Token (T1134.003)","Command and Scripting Interpreter: Cloud API (T1059.009)","Command and Scripting Interpreter: Cloud API (T1059.009)","Account Manipulation: Additional Cloud Credentials (T1098.001)""Account Manipulation: Additional Cloud Credentials (T1098.001)"],],"attackers_goals": "An attacker's goal is to gain unauthorized access, compromise user accounts, and perform malicious actions within an organization's systems, potentially leading to data breaches, account takeovers, and the escalation of privileges.","attackers_goals": "An attacker's goal is to gain unauthorized access, compromise user accounts, and perform malicious actions within an organization's systems, potentially leading to data breaches, account takeovers, and the escalation of privileges.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user created a new API token in Okta.","description": "A user created a new API token in Okta.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Review the actions taken by the user that created the token. Follow the operations made using this API token by the ID token. Contact the user who created the API token and ensure that the API token is needed.","investigative_actions": "Review the actions taken by the user that created the token. Follow the operations made using this API token by the ID token. Contact the user who created the API token and ensure that the API token is needed.","name": "Okta API Token Created","name": "Okta API Token Created","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -8,17 +8,17 @@ "attack_techniques": [ "Access Token Manipulation: Make and Impersonate Token (T1134.003)", "Command and Scripting Interpreter: Cloud API (T1059.009)", "Account Manipulation: Additional Cloud Credentials (T1098.001)" ], "attackers_goals": "An attacker's goal is to gain unauthorized access, compromise user accounts, and perform malicious actions within an organization's systems, potentially leading to data breaches, account takeovers, and the escalation of privileges.", "deduplication_period": "1 Day", "description": "A user created a new API token in Okta.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Review the actions taken by the user that created the token. Follow the operations made using this API token by the ID token. Contact the user who created the API token and ensure that the API token is needed.", "name": "Okta API Token Created", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Okta device assignment modified +1 −1
analytics/okta-device-assignmentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "For purposes of maintaining persistence, an attacker could potentially register his device with various accounts that have been compromised.","attackers_goals": "For purposes of maintaining persistence, an attacker could potentially register his device with various accounts that have been compromised.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A device was assigned as an Okta MFA device to a user.","description": "A device was assigned as an Okta MFA device to a user.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Confirm that the device assignments were intentionally made by the users and are legitimate. Examine the IP address and assess its reputation. Continue monitoring the accounts for any subsequent actions that may indicate suspicious behavior.","investigative_actions": "Confirm that the device assignments were intentionally made by the users and are legitimate. Examine the IP address and assess its reputation. Continue monitoring the accounts for any subsequent actions that may indicate suspicious behavior.","name": "Okta device assignment","name": "Okta device assignment","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "6 Hours","test_period": "6 Hours",Show markdown source
@@ -5,17 +5,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "For purposes of maintaining persistence, an attacker could potentially register his device with various accounts that have been compromised.", "deduplication_period": "1 Day", "description": "A device was assigned as an Okta MFA device to a user.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Confirm that the device assignments were intentionally made by the users and are legitimate. Examine the IP address and assess its reputation. Continue monitoring the accounts for any subsequent actions that may indicate suspicious behavior.", "name": "Okta device assignment", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "6 Hours", -
▸ ▾ Okta Reported Attack Suspected modified +1 −1
analytics/okta-reported-attack-suspectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker might attempt to compromise Okta accounts to gain access to sensitive assets or data.","attackers_goals": "An attacker might attempt to compromise Okta accounts to gain access to sensitive assets or data.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Okta Threat Insight Reported Attack Suspected.","description": "Okta Threat Insight Reported Attack Suspected.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Examine Okta alerts and search for signs of compromise to evaluate the potential risk.","investigative_actions": "Examine Okta alerts and search for signs of compromise to evaluate the potential risk.","name": "Okta Reported Attack Suspected","name": "Okta Reported Attack Suspected","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Low","severity": "Low","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An attacker might attempt to compromise Okta accounts to gain access to sensitive assets or data.", "deduplication_period": "1 Day", "description": "Okta Threat Insight Reported Attack Suspected.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Examine Okta alerts and search for signs of compromise to evaluate the potential risk.", "name": "Okta Reported Attack Suspected", "required_data": [ "Okta Audit Log" ], "severity": "Low", "test_period": "N/A (single event)", -
▸ ▾ Okta Reported Threat Detected modified +1 −1
analytics/okta-reported-threat-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.","attackers_goals": "An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Okta Threat Insight Reported Threat Detected.","description": "Okta Threat Insight Reported Threat Detected.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Investigate the original events that were reported as suspicious. Investigate additional alerts that are activated based on the IP address. Follow further actions done by the ip.","investigative_actions": "Investigate the original events that were reported as suspicious. Investigate additional alerts that are activated based on the IP address. Follow further actions done by the ip.","name": "Okta Reported Threat Detected","name": "Okta Reported Threat Detected","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "3 Hours","test_period": "3 Hours",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.", "deduplication_period": "1 Day", "description": "Okta Threat Insight Reported Threat Detected.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Investigate the original events that were reported as suspicious. Investigate additional alerts that are activated based on the IP address. Follow further actions done by the ip.", "name": "Okta Reported Threat Detected", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "3 Hours", -
▸ ▾ Okta User Session Impersonation modified +1 −1
analytics/okta-user-session-impersonationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Trusted Relationship (T1199)""Trusted Relationship (T1199)"],],"attackers_goals": "An attacker's goal is to gain unauthorized access to sensitive information or perform malicious actions on behalf of the impersonated user.","attackers_goals": "An attacker's goal is to gain unauthorized access to sensitive information or perform malicious actions on behalf of the impersonated user.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user has initiated a session impersonation in Okta.","description": "A user has initiated a session impersonation in Okta.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Ensure the user is authorized to impersonate a user session. Review any activities that occurred during the impersonation session. Look for any activities related to the impersonated user's account during and after the impersonation event.","investigative_actions": "Ensure the user is authorized to impersonate a user session. Review any activities that occurred during the impersonation session. Look for any activities related to the impersonated user's account during and after the impersonation event.","name": "Okta User Session Impersonation","name": "Okta User Session Impersonation","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Trusted Relationship (T1199)" ], "attackers_goals": "An attacker's goal is to gain unauthorized access to sensitive information or perform malicious actions on behalf of the impersonated user.", "deduplication_period": "1 Day", "description": "A user has initiated a session impersonation in Okta.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Ensure the user is authorized to impersonate a user session. Review any activities that occurred during the impersonation session. Look for any activities related to the impersonated user's account during and after the impersonation event.", "name": "Okta User Session Impersonation", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Owner added to Azure application modified +1 −1
analytics/owner-added-to-azure-applicationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Credential Access (TA0006)""Credential Access (TA0006)"],],"attack_techniques": ["attack_techniques": ["Steal Application Access Token (T1528)""Steal Application Access Token (T1528)"],],"attackers_goals": "An attacker may add owners to an application to authenticate as the application later on and access resources.","attackers_goals": "An attacker may add owners to an application to authenticate as the application later on and access resources.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity was added as an owner to an Azure application.","description": "An identity was added as an owner to an Azure application.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the added account is new to the organization. Check whether the account that added the new owner is supposed to perform such actions. Check for possible logins from the application modified. Follow further actions done by the application.","investigative_actions": "Check if the added account is new to the organization. Check whether the account that added the new owner is supposed to perform such actions. Check for possible logins from the application modified. Follow further actions done by the application.","name": "Owner added to Azure application","name": "Owner added to Azure application","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Credential Access (TA0006)" ], "attack_techniques": [ "Steal Application Access Token (T1528)" ], "attackers_goals": "An attacker may add owners to an application to authenticate as the application later on and access resources.", "deduplication_period": "1 Day", "description": "An identity was added as an owner to an Azure application.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the added account is new to the organization. Check whether the account that added the new owner is supposed to perform such actions. Check for possible logins from the application modified. Follow further actions done by the application.", "name": "Owner added to Azure application", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Possible Brute Force in universal authentication added +88 −0 New Identity Analytics detector for an abnormal volume of universal authentication attempts in an hour, with honey-user and baseline-deviation variations up to Medium.
analytics/possible-brute-force-in-universal-authenticationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -0,0 +1,88 @@{"activation_period": "14 Days","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force (T1110)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","deduplication_period": "1 Day","description": "An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.","detection_modules": "Identity Analytics","detector_tags": "","investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.","name": "Possible Brute Force in universal authentication","required_data": [],"severity": "Informational","test_period": "1 Hour","variations": [{"name": "Possible Brute Force in universal authentication on a honey user","severity": "Medium","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force (T1110)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"description": "An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.","attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts."},{"name": "Suspicious Brute Force in universal authentication","severity": "Medium","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force (T1110)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"description": "An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.","attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts."},{"name": "Brute Force in universal authentication","severity": "Low","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force (T1110)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"description": "An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.","attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts."},{"name": "Abnormal Possible Brute Force in universal authentication","severity": "Informational","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force (T1110)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"description": "The number of failed authentication attempts for this user significantly exceeds their historical baseline (avg + 3*stddev).","attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.","investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts."}]}Show markdown source
@@ -0,0 +1,88 @@ +{ + "activation_period": "14 Days", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force (T1110)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.", + "deduplication_period": "1 Day", + "description": "An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.", + "detection_modules": "Identity Analytics", + "detector_tags": "", + "investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.", + "name": "Possible Brute Force in universal authentication", + "required_data": [], + "severity": "Informational", + "test_period": "1 Hour", + "variations": [ + { + "name": "Possible Brute Force in universal authentication on a honey user", + "severity": "Medium", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force (T1110)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "description": "An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.", + "attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.", + "investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts." + }, + { + "name": "Suspicious Brute Force in universal authentication", + "severity": "Medium", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force (T1110)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "description": "An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.", + "attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.", + "investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts." + }, + { + "name": "Brute Force in universal authentication", + "severity": "Low", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force (T1110)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "description": "An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.", + "attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.", + "investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts." + }, + { + "name": "Abnormal Possible Brute Force in universal authentication", + "severity": "Informational", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force (T1110)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "description": "The number of failed authentication attempts for this user significantly exceeds their historical baseline (avg + 3*stddev).", + "attackers_goals": "An attacker is attempting to gain access to an account secured with MFA.", + "investigative_actions": "Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts." + } + ] +} -
▸ ▾ Possible ConsentFix - OAuth Token Theft Detected modified +1 −1
analytics/possible-consentfix-oauth-token-theft-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@"attack_techniques": ["attack_techniques": ["Phishing (T1566)","Phishing (T1566)","User Execution: Malicious Link (T1204.001)","User Execution: Malicious Link (T1204.001)","Steal Application Access Token (T1528)""Steal Application Access Token (T1528)"],],"attackers_goals": "Bypass identity trust controls to gain persistent unauthorized access to cloud resources.","attackers_goals": "Bypass identity trust controls to gain persistent unauthorized access to cloud resources.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session.","description": "Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check for successful logins to Azure CLI or PowerShell from anomalous IPs. Review sign-in logs for User-Agents associated with CLI tools or scripts. Revoke all active OAuth refresh tokens for the user immediately.","investigative_actions": "Check for successful logins to Azure CLI or PowerShell from anomalous IPs. Review sign-in logs for User-Agents associated with CLI tools or scripts. Revoke all active OAuth refresh tokens for the user immediately.","name": "Possible ConsentFix - OAuth Token Theft Detected","name": "Possible ConsentFix - OAuth Token Theft Detected","required_data": ["required_data": ["AzureAD""AzureAD"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -8,17 +8,17 @@ "attack_techniques": [ "Phishing (T1566)", "User Execution: Malicious Link (T1204.001)", "Steal Application Access Token (T1528)" ], "attackers_goals": "Bypass identity trust controls to gain persistent unauthorized access to cloud resources.", "deduplication_period": "1 Day", "description": "Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check for successful logins to Azure CLI or PowerShell from anomalous IPs. Review sign-in logs for User-Agents associated with CLI tools or scripts. Revoke all active OAuth refresh tokens for the user immediately.", "name": "Possible ConsentFix - OAuth Token Theft Detected", "required_data": [ "AzureAD" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ Possible Password Spray in universal authentication added +88 −0 New Identity Analytics detector for password spraying via universal authentication, with variations for honey users and for a spray followed by a successful authentication.
analytics/possible-password-spray-in-universal-authenticationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -0,0 +1,88 @@{"activation_period": "14 Days","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force: Password Spraying (T1110.003)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.","deduplication_period": "1 Day","description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.","detection_modules": "Identity Analytics","detector_tags": "","investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.","name": "Possible Password Spray in universal authentication","required_data": [],"severity": "Informational","test_period": "1 Hour","variations": [{"name": "Possible Password Spray in universal authentication Involving a Honey User","severity": "Medium","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force: Password Spraying (T1110.003)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.","attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.","investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts."},{"name": "Suspicious Password Spray in universal authentication","severity": "Medium","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force: Password Spraying (T1110.003)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.","attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.","investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts."},{"name": "Password Spray in universal authentication","severity": "Low","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force: Password Spraying (T1110.003)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.","attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.","investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts."},{"name": "Possible Password Spray in universal authentication with successful authentication","severity": "Informational","attack_tactics": ["Credential Access (TA0006)","Resource Development (TA0042)"],"attack_techniques": ["Brute Force: Password Spraying (T1110.003)","Brute Force: Password Guessing (T1110.001)","Compromise Accounts: Cloud Accounts (T1586.003)"],"description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.","attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.","investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts."}]}Show markdown source
@@ -0,0 +1,88 @@ +{ + "activation_period": "14 Days", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force: Password Spraying (T1110.003)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.", + "deduplication_period": "1 Day", + "description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.", + "detection_modules": "Identity Analytics", + "detector_tags": "", + "investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.", + "name": "Possible Password Spray in universal authentication", + "required_data": [], + "severity": "Informational", + "test_period": "1 Hour", + "variations": [ + { + "name": "Possible Password Spray in universal authentication Involving a Honey User", + "severity": "Medium", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force: Password Spraying (T1110.003)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.", + "attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.", + "investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts." + }, + { + "name": "Suspicious Password Spray in universal authentication", + "severity": "Medium", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force: Password Spraying (T1110.003)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.", + "attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.", + "investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts." + }, + { + "name": "Password Spray in universal authentication", + "severity": "Low", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force: Password Spraying (T1110.003)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.", + "attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.", + "investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts." + }, + { + "name": "Possible Password Spray in universal authentication with successful authentication", + "severity": "Informational", + "attack_tactics": [ + "Credential Access (TA0006)", + "Resource Development (TA0042)" + ], + "attack_techniques": [ + "Brute Force: Password Spraying (T1110.003)", + "Brute Force: Password Guessing (T1110.001)", + "Compromise Accounts: Cloud Accounts (T1586.003)" + ], + "description": "An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.", + "attackers_goals": "An attacker may be attempting to gain unauthorized access to user accounts.", + "investigative_actions": "Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts." + } + ] +} -
▸ ▾ Potential Okta access limit breach modified +1 −1
analytics/potential-okta-access-limit-breachRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Automated Collection (T1119)","Automated Collection (T1119)","Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An adversary may attempt to use a compromised account in an unusual way to harvest as much data as possible, which could result in exceeding the access limit policy.","attackers_goals": "An adversary may attempt to use a compromised account in an unusual way to harvest as much data as possible, which could result in exceeding the access limit policy.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt.","description": "A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Investigate abnormal logins, reported suspicious activities, new processes run, and recent configuration changes for any indicators of potential compromise. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN).","investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Investigate abnormal logins, reported suspicious activities, new processes run, and recent configuration changes for any indicators of potential compromise. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN).","name": "Potential Okta access limit breach","name": "Potential Okta access limit breach","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Automated Collection (T1119)", "Valid Accounts (T1078)" ], "attackers_goals": "An adversary may attempt to use a compromised account in an unusual way to harvest as much data as possible, which could result in exceeding the access limit policy.", "deduplication_period": "1 Day", "description": "A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Investigate abnormal logins, reported suspicious activities, new processes run, and recent configuration changes for any indicators of potential compromise. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN).", "name": "Potential Okta access limit breach", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Rare DLP rule match by user modified +1 −1
analytics/rare-dlp-rule-match-by-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Data from Information Repositories: Sharepoint (T1213.002)","Data from Information Repositories: Sharepoint (T1213.002)","Data from Information Repositories (T1213)""Data from Information Repositories (T1213)"],],"attackers_goals": "An attacker is attempting to access sensitive information.","attackers_goals": "An attacker is attempting to access sensitive information.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information.","description": "A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "O365 DLP Analytics","detector_tags": "O365 DLP Analytics","investigative_actions": "Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.","investigative_actions": "Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.","name": "Rare DLP rule match by user","name": "Rare DLP rule match by user","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Data from Information Repositories: Sharepoint (T1213.002)", "Data from Information Repositories (T1213)" ], "attackers_goals": "An attacker is attempting to access sensitive information.", "deduplication_period": "1 Day", "description": "A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "O365 DLP Analytics", "investigative_actions": "Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.", "name": "Rare DLP rule match by user", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ SaaS suspicious external domain user activity modified +1 −1
analytics/saas-suspicious-external-domain-user-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["External Remote Services (T1133)""External Remote Services (T1133)"],],"attackers_goals": "Gain their initial foothold within the organization and explore the environment to achieve their target.","attackers_goals": "Gain their initial foothold within the organization and explore the environment to achieve their target.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.","description": "An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Investigate the external domain name. Check the identity activity in the organization.","investigative_actions": "Investigate the external domain name. Check the identity activity in the organization.","name": "SaaS suspicious external domain user activity","name": "SaaS suspicious external domain user activity","required_data": ["required_data": ["Google Workspace Audit Logs","Google Workspace Audit Logs","Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -4,17 +4,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "External Remote Services (T1133)" ], "attackers_goals": "Gain their initial foothold within the organization and explore the environment to achieve their target.", "deduplication_period": "1 Day", "description": "An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Investigate the external domain name. Check the identity activity in the organization.", "name": "SaaS suspicious external domain user activity", "required_data": [ "Google Workspace Audit Logs", "Office 365 Audit" ], "severity": "Informational", -
▸ ▾ Security object deletion in Google Workspace Admin Console modified +1 −1
analytics/security-object-deletion-in-google-workspace-admin-consoleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Impair Defenses: Disable or Modify Tools (T1562.001)""Impair Defenses: Disable or Modify Tools (T1562.001)"],],"attackers_goals": "Adversaries may modify or disable security rules to avoid detection of their activities.","attackers_goals": "Adversaries may modify or disable security rules to avoid detection of their activities.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A security object was deleted in Google Workspace Admin Console.","description": "A security object was deleted in Google Workspace Admin Console.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Google Workspace","detector_tags": "Google Workspace","investigative_actions": "Investigate the security object name deleted and whether it was intended. Check if the user was recently granted new elevated permissions that allowed them to delete security rules. Follow other administrative or suspicious actions performed by this user around the same time.","investigative_actions": "Investigate the security object name deleted and whether it was intended. Check if the user was recently granted new elevated permissions that allowed them to delete security rules. Follow other administrative or suspicious actions performed by this user around the same time.","name": "Security object deletion in Google Workspace Admin Console","name": "Security object deletion in Google Workspace Admin Console","required_data": ["required_data": ["Google Workspace Audit Logs""Google Workspace Audit Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Impair Defenses: Disable or Modify Tools (T1562.001)" ], "attackers_goals": "Adversaries may modify or disable security rules to avoid detection of their activities.", "deduplication_period": "1 Day", "description": "A security object was deleted in Google Workspace Admin Console.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Google Workspace", "investigative_actions": "Investigate the security object name deleted and whether it was intended. Check if the user was recently granted new elevated permissions that allowed them to delete security rules. Follow other administrative or suspicious actions performed by this user around the same time.", "name": "Security object deletion in Google Workspace Admin Console", "required_data": [ "Google Workspace Audit Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Sensitive Exchange mail sent to external users modified +1 −1
analytics/sensitive-exchange-mail-sent-to-external-usersRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Email Collection (T1114)","Email Collection (T1114)","Exfiltration Over Alternative Protocol (T1048)""Exfiltration Over Alternative Protocol (T1048)"],],"attackers_goals": "An attacker is attempting to collect sensitive email information.","attackers_goals": "An attacker is attempting to collect sensitive email information.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user sent sensitive email messages to external users.","description": "A user sent sensitive email messages to external users.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "O365 DLP Analytics","detector_tags": "O365 DLP Analytics","investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.","investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.","name": "Sensitive Exchange mail sent to external users","name": "Sensitive Exchange mail sent to external users","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Email Collection (T1114)", "Exfiltration Over Alternative Protocol (T1048)" ], "attackers_goals": "An attacker is attempting to collect sensitive email information.", "deduplication_period": "1 Day", "description": "A user sent sensitive email messages to external users.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "O365 DLP Analytics", "investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.", "name": "Sensitive Exchange mail sent to external users", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ SharePoint Site Collection admin group addition modified +1 −1
analytics/sharepoint-site-collection-admin-group-additionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation: Additional Cloud Roles (T1098.003)""Account Manipulation: Additional Cloud Roles (T1098.003)"],],"attackers_goals": "Elevate permissions and establish persistence.","attackers_goals": "Elevate permissions and establish persistence.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user made an addition to the site collection administrators group in SharePoint.","description": "A user made an addition to the site collection administrators group in SharePoint.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check the IP address from which the access originated. Verify the activity with the performing user. Follow further actions done by the account.","investigative_actions": "Check the IP address from which the access originated. Verify the activity with the performing user. Follow further actions done by the account.","name": "SharePoint Site Collection admin group addition","name": "SharePoint Site Collection admin group addition","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Account Manipulation: Additional Cloud Roles (T1098.003)" ], "attackers_goals": "Elevate permissions and establish persistence.", "deduplication_period": "1 Day", "description": "A user made an addition to the site collection administrators group in SharePoint.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check the IP address from which the access originated. Verify the activity with the performing user. Follow further actions done by the account.", "name": "SharePoint Site Collection admin group addition", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Short-lived Azure AD user account modified +1 −1
analytics/short-lived-azure-ad-user-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Evasion using a valid account.","attackers_goals": "Evasion using a valid account.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An Azure AD user was created and deleted within a short period of time.","description": "An Azure AD user was created and deleted within a short period of time.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check the user who created the account and verify the activity. Confirm that the account creation was not accidental.","investigative_actions": "Check the user who created the account and verify the activity. Confirm that the account creation was not accidental.","name": "Short-lived Azure AD user account","name": "Short-lived Azure AD user account","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "Evasion using a valid account.", "deduplication_period": "1 Day", "description": "An Azure AD user was created and deleted within a short period of time.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check the user who created the account and verify the activity. Confirm that the account creation was not accidental.", "name": "Short-lived Azure AD user account", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ Successful universal authentication with suspicious features added +73 −0 New Identity Analytics detector for successful universal authentication flagged on anomalous features: TOR exit node, suspicious tunnel operator, unseen ASN, or new country.
analytics/successful-universal-authentication-with-suspicious-featuresRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -0,0 +1,73 @@{"activation_period": "14 Days","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts (T1078)"],"attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.","deduplication_period": "1 Day","description": "A universal authentication was flagged as suspicious based on anomalous features.","detection_modules": "Identity Analytics","detector_tags": "","investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN.","name": "Successful universal authentication with suspicious features","required_data": [],"severity": "Informational","test_period": "N/A (single event)","variations": [{"name": "Successful universal authentication sign-in from a TOR exit node","severity": "Medium","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts (T1078)"],"description": "A successful sign-in from a TOR exit node in universal authentication.","attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.","investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN."},{"name": "Successful universal authentication from a suspicious tunnel operator","severity": "Low","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts (T1078)"],"description": "A successful universal authentication was made through a suspicious or rarely seen tunnel operator.","attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.","investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN."},{"name": "Suspicious successful universal authentication from ASN","severity": "Informational","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts (T1078)"],"description": "A successful universal authentication was made from a suspicious or previously unseen ASN.","attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.","investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN."},{"name": "Successful universal authentication from a new country in organization","severity": "Informational","attack_tactics": ["Initial Access (TA0001)"],"attack_techniques": ["Valid Accounts (T1078)"],"description": "A user authenticated in universal authentication from an unusual country that no one from this organization has connected from before in universal authentication. This may indicate the account was compromised.","attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.","investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN."}]}Show markdown source
@@ -0,0 +1,73 @@ +{ + "activation_period": "14 Days", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts (T1078)" + ], + "attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.", + "deduplication_period": "1 Day", + "description": "A universal authentication was flagged as suspicious based on anomalous features.", + "detection_modules": "Identity Analytics", + "detector_tags": "", + "investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN.", + "name": "Successful universal authentication with suspicious features", + "required_data": [], + "severity": "Informational", + "test_period": "N/A (single event)", + "variations": [ + { + "name": "Successful universal authentication sign-in from a TOR exit node", + "severity": "Medium", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts (T1078)" + ], + "description": "A successful sign-in from a TOR exit node in universal authentication.", + "attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.", + "investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN." + }, + { + "name": "Successful universal authentication from a suspicious tunnel operator", + "severity": "Low", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts (T1078)" + ], + "description": "A successful universal authentication was made through a suspicious or rarely seen tunnel operator.", + "attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.", + "investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN." + }, + { + "name": "Suspicious successful universal authentication from ASN", + "severity": "Informational", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts (T1078)" + ], + "description": "A successful universal authentication was made from a suspicious or previously unseen ASN.", + "attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.", + "investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN." + }, + { + "name": "Successful universal authentication from a new country in organization", + "severity": "Informational", + "attack_tactics": [ + "Initial Access (TA0001)" + ], + "attack_techniques": [ + "Valid Accounts (T1078)" + ], + "description": "A user authenticated in universal authentication from an unusual country that no one from this organization has connected from before in universal authentication. This may indicate the account was compromised.", + "attackers_goals": "Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.", + "investigative_actions": "Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN." + } + ] +} -
▸ ▾ Successful unusual guest user invitation modified +1 −1
analytics/successful-unusual-guest-user-invitationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker can invite users to for evasion.","attackers_goals": "An attacker can invite users to for evasion.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity successfully invited a guest user to the tenant with unusual characteristics.","description": "An identity successfully invited a guest user to the tenant with unusual characteristics.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check who is the invited guest user. Check whether the inviter is permitted to perform such actions. Check if the domain of the invited guest is allowed for invitations in the organization.","investigative_actions": "Check who is the invited guest user. Check whether the inviter is permitted to perform such actions. Check if the domain of the invited guest is allowed for invitations in the organization.","name": "Successful unusual guest user invitation","name": "Successful unusual guest user invitation","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An attacker can invite users to for evasion.", "deduplication_period": "1 Day", "description": "An identity successfully invited a guest user to the tenant with unusual characteristics.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check who is the invited guest user. Check whether the inviter is permitted to perform such actions. Check if the domain of the invited guest is allowed for invitations in the organization.", "name": "Successful unusual guest user invitation", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Suspicious activity on logging bucket modified +1 −1
analytics/suspicious-activity-on-logging-bucketRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@"attack_techniques": ["attack_techniques": ["Impair Defenses (T1562)","Impair Defenses (T1562)","Impair Defenses: Disable or Modify Cloud Logs (T1562.008)""Impair Defenses: Disable or Modify Cloud Logs (T1562.008)"],],"attackers_goals": "Evade detection by tampering the logs.","attackers_goals": "Evade detection by tampering the logs.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity performed a suspicious activity on bucket used to store logs.","description": "An identity performed a suspicious activity on bucket used to store logs.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "Cloud Log Tampering Analytics","investigative_actions": "Verify whether the identity attempted to access the bucket. Verify no logs were modified in the bucket.","investigative_actions": "Verify whether the identity attempted to access the bucket. Verify no logs were modified in the bucket.","name": "Suspicious activity on logging bucket","name": "Suspicious activity on logging bucket","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": ["variations": [Show markdown source
@@ -6,17 +6,17 @@ "attack_techniques": [ "Impair Defenses (T1562)", "Impair Defenses: Disable or Modify Cloud Logs (T1562.008)" ], "attackers_goals": "Evade detection by tampering the logs.", "deduplication_period": "1 Day", "description": "An identity performed a suspicious activity on bucket used to store logs.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "Cloud Log Tampering Analytics", "investigative_actions": "Verify whether the identity attempted to access the bucket. Verify no logs were modified in the bucket.", "name": "Suspicious activity on logging bucket", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [ -
▸ ▾ Suspicious API call from a Tor exit node modified +1 −1
analytics/suspicious-api-call-from-a-tor-exit-nodeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Proxy: Multi-hop Proxy (T1090.003)","Proxy: Multi-hop Proxy (T1090.003)","Valid Accounts: Cloud Accounts (T1078.004)""Valid Accounts: Cloud Accounts (T1078.004)"],],"attackers_goals": "Conceal information about malicious activities, such as location and network usage.","attackers_goals": "Conceal information about malicious activities, such as location and network usage.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A cloud API was called from a Tor exit node.","description": "A cloud API was called from a Tor exit node.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "Kubernetes - API","detector_tags": "Kubernetes - API, OCI Analytics","investigative_actions": "Block all web traffic to and from public Tor entry and exit nodes.","investigative_actions": "Block all web traffic to and from public Tor entry and exit nodes.","name": "Suspicious API call from a Tor exit node","name": "Suspicious API call from a Tor exit node","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log","Gcp Audit Log","Kubernetes Audit Logs""Kubernetes Audit Logs"],],Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Proxy: Multi-hop Proxy (T1090.003)", "Valid Accounts: Cloud Accounts (T1078.004)" ], "attackers_goals": "Conceal information about malicious activities, such as location and network usage.", "deduplication_period": "1 Day", "description": "A cloud API was called from a Tor exit node.", "detection_modules": "Cloud", - "detector_tags": "Kubernetes - API", + "detector_tags": "Kubernetes - API, OCI Analytics", "investigative_actions": "Block all web traffic to and from public Tor entry and exit nodes.", "name": "Suspicious API call from a Tor exit node", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log", "Kubernetes Audit Logs" ], -
▸ ▾ Suspicious AWS SSM parameters retrieval activity modified +1 −1
analytics/suspicious-aws-ssm-parameters-retrieval-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Unsecured Credentials (T1552)","Unsecured Credentials (T1552)","Data from Cloud Storage (T1530)""Data from Cloud Storage (T1530)"],],"attackers_goals": "Collect secrets from the cloud environment.","attackers_goals": "Collect secrets from the cloud environment.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.","description": "An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "SSM Remote Management Analytics","investigative_actions": "Check the accessed parameters' designation. Verify that the identity did not dump any sensitive information that it shouldn't.","investigative_actions": "Check the accessed parameters' designation. Verify that the identity did not dump any sensitive information that it shouldn't.","name": "Suspicious AWS SSM parameters retrieval activity","name": "Suspicious AWS SSM parameters retrieval activity","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour","variations": ["variations": [Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Unsecured Credentials (T1552)", "Data from Cloud Storage (T1530)" ], "attackers_goals": "Collect secrets from the cloud environment.", "deduplication_period": "5 Days", "description": "An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "SSM Remote Management Analytics", "investigative_actions": "Check the accessed parameters' designation. Verify that the identity did not dump any sensitive information that it shouldn't.", "name": "Suspicious AWS SSM parameters retrieval activity", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "1 Hour", "variations": [ -
▸ ▾ Suspicious MFA request reported by user in Entra ID modified +1 −1
analytics/suspicious-mfa-request-reported-by-user-in-entra-idRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@"Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "An attacker may attempt to gain unauthorized access to the account.","attackers_goals": "An attacker may attempt to gain unauthorized access to the account.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt.","description": "A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the authentication attempt was legitimate. Investigate any recent unusual login behavior or IP addresses associated with the account. Verify whether the user has recently changed their authentication methods or account settings. Follow the account for possible suspicious or unusual logins.","investigative_actions": "Check if the authentication attempt was legitimate. Investigate any recent unusual login behavior or IP addresses associated with the account. Verify whether the user has recently changed their authentication methods or account settings. Follow the account for possible suspicious or unusual logins.","name": "Suspicious MFA request reported by user in Entra ID","name": "Suspicious MFA request reported by user in Entra ID","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ "Initial Access (TA0001)" ], "attack_techniques": [ "Valid Accounts (T1078)" ], "attackers_goals": "An attacker may attempt to gain unauthorized access to the account.", "deduplication_period": "1 Day", "description": "A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the authentication attempt was legitimate. Investigate any recent unusual login behavior or IP addresses associated with the account. Verify whether the user has recently changed their authentication methods or account settings. Follow the account for possible suspicious or unusual logins.", "name": "Suspicious MFA request reported by user in Entra ID", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Suspicious SaaS API call from a Tor exit node modified +1 −1
analytics/suspicious-saas-api-call-from-a-tor-exit-nodeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Command and Control (TA0011)""Command and Control (TA0011)"],],"attack_techniques": ["attack_techniques": ["Proxy: Multi-hop Proxy (T1090.003)""Proxy: Multi-hop Proxy (T1090.003)"],],"attackers_goals": "Conceal information about malicious activities, such as location and network usage.","attackers_goals": "Conceal information about malicious activities, such as location and network usage.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A SaaS API was called from a Tor exit node.","description": "A SaaS API was called from a Tor exit node.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Block all web traffic to and from public Tor entry and exit nodes.","investigative_actions": "Block all web traffic to and from public Tor entry and exit nodes.","name": "Suspicious SaaS API call from a Tor exit node","name": "Suspicious SaaS API call from a Tor exit node","required_data": ["required_data": ["Box Audit Log","Box Audit Log","DropBox","DropBox","Google Workspace Audit Logs","Google Workspace Audit Logs","Office 365 Audit""Office 365 Audit"Show markdown source
@@ -4,17 +4,17 @@ "Command and Control (TA0011)" ], "attack_techniques": [ "Proxy: Multi-hop Proxy (T1090.003)" ], "attackers_goals": "Conceal information about malicious activities, such as location and network usage.", "deduplication_period": "1 Day", "description": "A SaaS API was called from a Tor exit node.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Block all web traffic to and from public Tor entry and exit nodes.", "name": "Suspicious SaaS API call from a Tor exit node", "required_data": [ "Box Audit Log", "DropBox", "Google Workspace Audit Logs", "Office 365 Audit" -
▸ ▾ Unrecognized internal address (AAD mismatch) modified +1 −1 Deduplication period narrowed from 1 Day to 1 Hour 30 Minutes; no other field changed.
analytics/unrecognized-internal-address-aad-mismatchRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -2,17 +2,17 @@"activation_period": "14 Days","activation_period": "14 Days","attack_tactics": ["attack_tactics": ["Initial Access (TA0001)""Initial Access (TA0001)"],],"attack_techniques": ["attack_techniques": ["Phishing (T1566)""Phishing (T1566)"],],"attackers_goals": "The attacker aims to impersonate an internal user to gain trust, bypass security controls, and potentially extract sensitive information or distribute malicious content through internal-looking emails.","attackers_goals": "The attacker aims to impersonate an internal user to gain trust, bypass security controls, and potentially extract sensitive information or distribute malicious content through internal-looking emails.","deduplication_period": "1 Day","deduplication_period": "1 Hour 30 Minutes","description": "An email was received from an address using an internal domain, but the sender is not found in Active Directory. This may indicate an impersonation attempt or domain spoofing.","description": "An email was received from an address using an internal domain, but the sender is not found in Active Directory. This may indicate an impersonation attempt or domain spoofing.","detection_modules": "Email","detection_modules": "Email","detector_tags": "Employee Impersonation, Spear Phishing","detector_tags": "Employee Impersonation, Spear Phishing","investigative_actions": "Verify if the sender address exists in Active Directory. Check historical email activity from the spoofed address. Review email headers for spoofing indicators (SPF, DKIM, DMARC failures). Identify if recipients engaged with the email (clicked links, downloaded attachments). Correlate with other alerts involving the same sender or domain.","investigative_actions": "Verify if the sender address exists in Active Directory. Check historical email activity from the spoofed address. Review email headers for spoofing indicators (SPF, DKIM, DMARC failures). Identify if recipients engaged with the email (clicked links, downloaded attachments). Correlate with other alerts involving the same sender or domain.","name": "Unrecognized internal address (AAD mismatch)","name": "Unrecognized internal address (AAD mismatch)","required_data": ["required_data": ["Microsoft 365 Emails""Microsoft 365 Emails"],],Show markdown source
@@ -2,17 +2,17 @@ "activation_period": "14 Days", "attack_tactics": [ "Initial Access (TA0001)" ], "attack_techniques": [ "Phishing (T1566)" ], "attackers_goals": "The attacker aims to impersonate an internal user to gain trust, bypass security controls, and potentially extract sensitive information or distribute malicious content through internal-looking emails.", - "deduplication_period": "1 Day", + "deduplication_period": "1 Hour 30 Minutes", "description": "An email was received from an address using an internal domain, but the sender is not found in Active Directory. This may indicate an impersonation attempt or domain spoofing.", "detection_modules": "Email", "detector_tags": "Employee Impersonation, Spear Phishing", "investigative_actions": "Verify if the sender address exists in Active Directory. Check historical email activity from the spoofed address. Review email headers for spoofing indicators (SPF, DKIM, DMARC failures). Identify if recipients engaged with the email (clicked links, downloaded attachments). Correlate with other alerts involving the same sender or domain.", "name": "Unrecognized internal address (AAD mismatch)", "required_data": [ "Microsoft 365 Emails" ], -
▸ ▾ Unusual AWS systems manager activity modified +1 −1
analytics/unusual-aws-systems-manager-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -7,17 +7,17 @@"attack_techniques": ["attack_techniques": ["Cloud Service Discovery (T1526)","Cloud Service Discovery (T1526)","Remote Services: Cloud Services (T1021.007)""Remote Services: Cloud Services (T1021.007)"],],"attackers_goals": "Manipulate SSM operations to take control over EC2 instances and strengthen the foothold in the cloud environment of the organization, by running critical operating system commands, manipulating the parameters store, and patch management configuration.","attackers_goals": "Manipulate SSM operations to take control over EC2 instances and strengthen the foothold in the cloud environment of the organization, by running critical operating system commands, manipulating the parameters store, and patch management configuration.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A cloud identity performed an SSM operation for the first time.","description": "A cloud identity performed an SSM operation for the first time.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "SSM Remote Management Analytics","investigative_actions": "Check the identity's role designation in the organization. Verify that the identity did not perform any sensitive SSM operation that it shouldn't.","investigative_actions": "Check the identity's role designation in the organization. Verify that the identity did not perform any sensitive SSM operation that it shouldn't.","name": "Unusual AWS systems manager activity","name": "Unusual AWS systems manager activity","required_data": ["required_data": ["AWS Audit Log""AWS Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)","variations": []"variations": []Show markdown source
@@ -7,17 +7,17 @@ "attack_techniques": [ "Cloud Service Discovery (T1526)", "Remote Services: Cloud Services (T1021.007)" ], "attackers_goals": "Manipulate SSM operations to take control over EC2 instances and strengthen the foothold in the cloud environment of the organization, by running critical operating system commands, manipulating the parameters store, and patch management configuration.", "deduplication_period": "1 Day", "description": "A cloud identity performed an SSM operation for the first time.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "SSM Remote Management Analytics", "investigative_actions": "Check the identity's role designation in the organization. Verify that the identity did not perform any sensitive SSM operation that it shouldn't.", "name": "Unusual AWS systems manager activity", "required_data": [ "AWS Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", "variations": [] -
▸ ▾ Unusual Conditional Access operation for an identity modified +1 −1
analytics/unusual-conditional-access-operation-for-an-identityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Abuse Elevation Control Mechanism (T1548)""Abuse Elevation Control Mechanism (T1548)"],],"attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. With a modified Conditional Access policy, an attacker might be able to access the tenant without possible blockage for later access.","attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. With a modified Conditional Access policy, an attacker might be able to access the tenant without possible blockage for later access.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "An identity attempted to add or update an Azure AD Conditional Access policy.","description": "An identity attempted to add or update an Azure AD Conditional Access policy.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check implications of the updated policy. Check whether the user changing the configuration is permitted to perform such actions.","investigative_actions": "Check implications of the updated policy. Check whether the user changing the configuration is permitted to perform such actions.","name": "Unusual Conditional Access operation for an identity","name": "Unusual Conditional Access operation for an identity","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Abuse Elevation Control Mechanism (T1548)" ], "attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion. With a modified Conditional Access policy, an attacker might be able to access the tenant without possible blockage for later access.", "deduplication_period": "1 Day", "description": "An identity attempted to add or update an Azure AD Conditional Access policy.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check implications of the updated policy. Check whether the user changing the configuration is permitted to perform such actions.", "name": "Unusual Conditional Access operation for an identity", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ Unusual resource modification by newly seen IAM user modified +1 −1
analytics/unusual-resource-modification-by-newly-seen-iam-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@"attack_techniques": ["attack_techniques": ["Valid Accounts: Cloud Accounts (T1078.004)","Valid Accounts: Cloud Accounts (T1078.004)","Data Destruction (T1485)""Data Destruction (T1485)"],],"attackers_goals": "Leverage access to manipulate cloud infrastructure.","attackers_goals": "Leverage access to manipulate cloud infrastructure.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A cloud resource was modified by a newly seen IAM user.","description": "A cloud resource was modified by a newly seen IAM user.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Examine which resources were affected and how. Investigate any unusual activity originating from the identity.","investigative_actions": "Examine which resources were affected and how. Investigate any unusual activity originating from the identity.","name": "Unusual resource modification by newly seen IAM user","name": "Unusual resource modification by newly seen IAM user","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -8,17 +8,17 @@ "attack_techniques": [ "Valid Accounts: Cloud Accounts (T1078.004)", "Data Destruction (T1485)" ], "attackers_goals": "Leverage access to manipulate cloud infrastructure.", "deduplication_period": "5 Days", "description": "A cloud resource was modified by a newly seen IAM user.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Examine which resources were affected and how. Investigate any unusual activity originating from the identity.", "name": "Unusual resource modification by newly seen IAM user", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "Informational", -
▸ ▾ Unusual user-agent for a cloud identity modified +1 −1
analytics/unusual-user-agent-for-a-cloud-identityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -8,17 +8,17 @@],],"attack_techniques": ["attack_techniques": ["Valid Accounts: Cloud Accounts (T1078.004)""Valid Accounts: Cloud Accounts (T1078.004)"],],"attackers_goals": "Evade detection by using non-standard tools or scripts.","attackers_goals": "Evade detection by using non-standard tools or scripts.","deduplication_period": "5 Days","deduplication_period": "5 Days","description": "A cloud identity has executed an API call with an unusual user-agent.","description": "A cloud identity has executed an API call with an unusual user-agent.","detection_modules": "Cloud","detection_modules": "Cloud","detector_tags": "","detector_tags": "OCI Analytics","investigative_actions": "Examine the recent actions of the user for any abnormal or unauthorized behavior. Verify if the user intentionally used a new device or tool.","investigative_actions": "Examine the recent actions of the user for any abnormal or unauthorized behavior. Verify if the user intentionally used a new device or tool.","name": "Unusual user-agent for a cloud identity","name": "Unusual user-agent for a cloud identity","required_data": ["required_data": ["AWS Audit Log","AWS Audit Log","Azure Audit Log","Azure Audit Log","Gcp Audit Log""Gcp Audit Log"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -8,17 +8,17 @@ ], "attack_techniques": [ "Valid Accounts: Cloud Accounts (T1078.004)" ], "attackers_goals": "Evade detection by using non-standard tools or scripts.", "deduplication_period": "5 Days", "description": "A cloud identity has executed an API call with an unusual user-agent.", "detection_modules": "Cloud", - "detector_tags": "", + "detector_tags": "OCI Analytics", "investigative_actions": "Examine the recent actions of the user for any abnormal or unauthorized behavior. Verify if the user intentionally used a new device or tool.", "name": "Unusual user-agent for a cloud identity", "required_data": [ "AWS Audit Log", "Azure Audit Log", "Gcp Audit Log" ], "severity": "Informational", -
▸ ▾ Unverified domain added to Azure AD modified +1 −1
analytics/unverified-domain-added-to-azure-adRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Account Manipulation: Additional Cloud Credentials (T1098.001)""Account Manipulation: Additional Cloud Credentials (T1098.001)"],],"attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion.","attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion.","deduplication_period": "1 Hour","deduplication_period": "1 Hour","description": "A new unverified domain was added to Azure AD.","description": "A new unverified domain was added to Azure AD.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if the new domain is known for the organization. Check whether the user changing the configuration is permitted. Monitor network activity to and from the added domain.","investigative_actions": "Check if the new domain is known for the organization. Check whether the user changing the configuration is permitted. Monitor network activity to and from the added domain.","name": "Unverified domain added to Azure AD","name": "Unverified domain added to Azure AD","required_data": ["required_data": ["AzureAD Audit Log""AzureAD Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Account Manipulation: Additional Cloud Credentials (T1098.001)" ], "attackers_goals": "An attacker attempts to change Active Directory configuration for persistence or defense evasion.", "deduplication_period": "1 Hour", "description": "A new unverified domain was added to Azure AD.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if the new domain is known for the organization. Check whether the user changing the configuration is permitted. Monitor network activity to and from the added domain.", "name": "Unverified domain added to Azure AD", "required_data": [ "AzureAD Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ User accessed multiple O365 AIP sensitive files modified +1 −1
analytics/user-accessed-multiple-o365-aip-sensitive-filesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Data from Information Repositories (T1213)","Data from Information Repositories (T1213)","Data from Local System (T1005)""Data from Local System (T1005)"],],"attackers_goals": "An attacker is attempting to collect sensitive information.","attackers_goals": "An attacker is attempting to collect sensitive information.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user accessed multiple O365 AIP sensitive files.","description": "A user accessed multiple O365 AIP sensitive files.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "O365 DLP Analytics","detector_tags": "O365 DLP Analytics","investigative_actions": "Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Check what sensitivity labels are detected and how suspicious they are. Examine the user's account history for suspicious behavior.","investigative_actions": "Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Check what sensitivity labels are detected and how suspicious they are. Examine the user's account history for suspicious behavior.","name": "User accessed multiple O365 AIP sensitive files","name": "User accessed multiple O365 AIP sensitive files","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Data from Information Repositories (T1213)", "Data from Local System (T1005)" ], "attackers_goals": "An attacker is attempting to collect sensitive information.", "deduplication_period": "1 Day", "description": "A user accessed multiple O365 AIP sensitive files.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "O365 DLP Analytics", "investigative_actions": "Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Check what sensitivity labels are detected and how suspicious they are. Examine the user's account history for suspicious behavior.", "name": "User accessed multiple O365 AIP sensitive files", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ User accessed SaaS resource via anonymous link modified +1 −1
analytics/user-accessed-saas-resource-via-anonymous-linkRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Collection (TA0009)""Collection (TA0009)"],],"attack_techniques": ["attack_techniques": ["Data from Cloud Storage (T1530)""Data from Cloud Storage (T1530)"],],"attackers_goals": "An attacker is attempting to collect sensitive data.","attackers_goals": "An attacker is attempting to collect sensitive data.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user accessed a SaaS resource via an anonymous link.","description": "A user accessed a SaaS resource via an anonymous link.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check the IP address from which the access originated. Examine the file that was accessed for any sensitive indicators. Follow further actions taken, such as downloading files.","investigative_actions": "Check the IP address from which the access originated. Examine the file that was accessed for any sensitive indicators. Follow further actions taken, such as downloading files.","name": "User accessed SaaS resource via anonymous link","name": "User accessed SaaS resource via anonymous link","required_data": ["required_data": ["Google Workspace Audit Logs","Google Workspace Audit Logs","Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational",Show markdown source
@@ -4,17 +4,17 @@ "Collection (TA0009)" ], "attack_techniques": [ "Data from Cloud Storage (T1530)" ], "attackers_goals": "An attacker is attempting to collect sensitive data.", "deduplication_period": "1 Day", "description": "A user accessed a SaaS resource via an anonymous link.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check the IP address from which the access originated. Examine the file that was accessed for any sensitive indicators. Follow further actions taken, such as downloading files.", "name": "User accessed SaaS resource via anonymous link", "required_data": [ "Google Workspace Audit Logs", "Office 365 Audit" ], "severity": "Informational", -
▸ ▾ User added a new device to Okta Verify instance modified +1 −1
analytics/user-added-a-new-device-to-okta-verify-instanceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -5,17 +5,17 @@],],"attack_techniques": ["attack_techniques": ["Account Manipulation (T1098)","Account Manipulation (T1098)","Valid Accounts (T1078)""Valid Accounts (T1078)"],],"attackers_goals": "Attackers may exploit the device registration process in Okta by registering unauthorized devices, thereby gaining access to sensitive resources and user accounts within an organization.","attackers_goals": "Attackers may exploit the device registration process in Okta by registering unauthorized devices, thereby gaining access to sensitive resources and user accounts within an organization.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "The user has successfully registered a new device with the Okta Verify application.","description": "The user has successfully registered a new device with the Okta Verify application.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Okta Audit Analytics","detector_tags": "Okta Audit Analytics","investigative_actions": "Reach out to the user responsible for the device registration to confirm its legitimacy. Examine the user's actions preceding and following the activation of the alert. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN). Make sure the IP address is not showing any abnormal activity. Monitor the activity from the new registered device and ensure that it matches the user's normal activity.","investigative_actions": "Reach out to the user responsible for the device registration to confirm its legitimacy. Examine the user's actions preceding and following the activation of the alert. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN). Make sure the IP address is not showing any abnormal activity. Monitor the activity from the new registered device and ensure that it matches the user's normal activity.","name": "User added a new device to Okta Verify instance","name": "User added a new device to Okta Verify instance","required_data": ["required_data": ["Okta Audit Log""Okta Audit Log"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -5,17 +5,17 @@ ], "attack_techniques": [ "Account Manipulation (T1098)", "Valid Accounts (T1078)" ], "attackers_goals": "Attackers may exploit the device registration process in Okta by registering unauthorized devices, thereby gaining access to sensitive resources and user accounts within an organization.", "deduplication_period": "1 Day", "description": "The user has successfully registered a new device with the Okta Verify application.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Okta Audit Analytics", "investigative_actions": "Reach out to the user responsible for the device registration to confirm its legitimacy. Examine the user's actions preceding and following the activation of the alert. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN). Make sure the IP address is not showing any abnormal activity. Monitor the activity from the new registered device and ensure that it matches the user's normal activity.", "name": "User added a new device to Okta Verify instance", "required_data": [ "Okta Audit Log" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ User exported multiple messages in Microsoft Teams via Graph API modified +1 −1
analytics/user-exported-multiple-messages-in-microsoft-teams-via-graph-apiRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Collection (TA0009)""Collection (TA0009)"],],"attack_techniques": ["attack_techniques": ["Data from Information Repositories: Messaging Applications (T1213.005)""Data from Information Repositories: Messaging Applications (T1213.005)"],],"attackers_goals": "Attackers may leverage messages extraction from Microsoft Teams to collect sensitive data.","attackers_goals": "Attackers may leverage messages extraction from Microsoft Teams to collect sensitive data.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user exported multiple messages in Microsoft Teams via Graph API.","description": "A user exported multiple messages in Microsoft Teams via Graph API.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.","investigative_actions": "Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.","name": "User exported multiple messages in Microsoft Teams via Graph API","name": "User exported multiple messages in Microsoft Teams via Graph API","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -4,17 +4,17 @@ "Collection (TA0009)" ], "attack_techniques": [ "Data from Information Repositories: Messaging Applications (T1213.005)" ], "attackers_goals": "Attackers may leverage messages extraction from Microsoft Teams to collect sensitive data.", "deduplication_period": "1 Day", "description": "A user exported multiple messages in Microsoft Teams via Graph API.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.", "name": "User exported multiple messages in Microsoft Teams via Graph API", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ User installed an application in Microsoft Teams via Graph API modified +1 −1
analytics/user-installed-an-application-in-microsoft-teams-via-graph-apiRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Persistence (TA0003)""Persistence (TA0003)"],],"attack_techniques": ["attack_techniques": ["Cloud Application Integration (T1671)""Cloud Application Integration (T1671)"],],"attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.","attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user who rarely uses the Graph API to install Microsoft Teams applications has installed one using it.","description": "A user who rarely uses the Graph API to install Microsoft Teams applications has installed one using it.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Verify the user's role and typical usage of Microsoft Graph API. Check if the user's account has recently logged in from unusual locations or devices. Review recent email and chat activity to identify any phishing or suspicious messages sent. Examine the Graph API call logs to see what actions were performed and their timestamps. Correlate with endpoint logs to detect any malware or suspicious processes running on the user's device. Check for signs of account compromise, such as password changes or MFA bypass attempts. Follow further actions done by the account.","investigative_actions": "Verify the user's role and typical usage of Microsoft Graph API. Check if the user's account has recently logged in from unusual locations or devices. Review recent email and chat activity to identify any phishing or suspicious messages sent. Examine the Graph API call logs to see what actions were performed and their timestamps. Correlate with endpoint logs to detect any malware or suspicious processes running on the user's device. Check for signs of account compromise, such as password changes or MFA bypass attempts. Follow further actions done by the account.","name": "User installed an application in Microsoft Teams via Graph API","name": "User installed an application in Microsoft Teams via Graph API","required_data": ["required_data": ["Microsoft Graph Logs""Microsoft Graph Logs"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -4,17 +4,17 @@ "Persistence (TA0003)" ], "attack_techniques": [ "Cloud Application Integration (T1671)" ], "attackers_goals": "Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.", "deduplication_period": "1 Day", "description": "A user who rarely uses the Graph API to install Microsoft Teams applications has installed one using it.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Verify the user's role and typical usage of Microsoft Graph API. Check if the user's account has recently logged in from unusual locations or devices. Review recent email and chat activity to identify any phishing or suspicious messages sent. Examine the Graph API call logs to see what actions were performed and their timestamps. Correlate with endpoint logs to detect any malware or suspicious processes running on the user's device. Check for signs of account compromise, such as password changes or MFA bypass attempts. Follow further actions done by the account.", "name": "User installed an application in Microsoft Teams via Graph API", "required_data": [ "Microsoft Graph Logs" ], "severity": "Informational", "test_period": "N/A (single event)", -
▸ ▾ User moved Exchange sent messages to deleted items modified +1 −1
analytics/user-moved-exchange-sent-messages-to-deleted-itemsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Defense Evasion (TA0005)""Defense Evasion (TA0005)"],],"attack_techniques": ["attack_techniques": ["Indicator Removal: Clear Mailbox Data (T1070.008)""Indicator Removal: Clear Mailbox Data (T1070.008)"],],"attackers_goals": "An attacker is attempting to hide newly sent email messages for evasion purposes.","attackers_goals": "An attacker is attempting to hide newly sent email messages for evasion purposes.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user moved sent messages to deleted items in Exchange.","description": "A user moved sent messages to deleted items in Exchange.","detection_modules": "Identity Threat Module, Email","detection_modules": "Identity Threat Module, SaaS Threat Detection, Email","detector_tags": "","detector_tags": "","investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.","investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.","name": "User moved Exchange sent messages to deleted items","name": "User moved Exchange sent messages to deleted items","required_data": ["required_data": ["Office 365 Audit""Office 365 Audit"],],"severity": "Informational","severity": "Informational","test_period": "10 Minutes","test_period": "10 Minutes",Show markdown source
@@ -4,17 +4,17 @@ "Defense Evasion (TA0005)" ], "attack_techniques": [ "Indicator Removal: Clear Mailbox Data (T1070.008)" ], "attackers_goals": "An attacker is attempting to hide newly sent email messages for evasion purposes.", "deduplication_period": "1 Day", "description": "A user moved sent messages to deleted items in Exchange.", - "detection_modules": "Identity Threat Module, Email", + "detection_modules": "Identity Threat Module, SaaS Threat Detection, Email", "detector_tags": "", "investigative_actions": "Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.", "name": "User moved Exchange sent messages to deleted items", "required_data": [ "Office 365 Audit" ], "severity": "Informational", "test_period": "10 Minutes", -
▸ ▾ User sent messages in Microsoft Teams to multiple conversations via Graph API modified +1 −1
analytics/user-sent-messages-in-microsoft-teams-to-multiple-conversations-via-graph-apiRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -4,17 +4,17 @@"Lateral Movement (TA0008)""Lateral Movement (TA0008)"],],"attack_techniques": ["attack_techniques": ["Internal Spearphishing (T1534)""Internal Spearphishing (T1534)"],],"attackers_goals": "Attackers may leverage a compromised user account to send phishing or malicious messages via Graph API to multiple recipients, aiming to propagate the attack while evading detection.","attackers_goals": "Attackers may leverage a compromised user account to send phishing or malicious messages via Graph API to multiple recipients, aiming to propagate the attack while evading detection.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user who rarely uses the Graph API for Microsoft Teams messaging sent multiple messages using it.","description": "A user who rarely uses the Graph API for Microsoft Teams messaging sent multiple messages using it.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "Microsoft Teams","detector_tags": "Microsoft Teams","investigative_actions": "Verify the user's role and typical usage of Microsoft Graph API. Check if the user's account has recently logged in from unusual locations or devices. Review recent email and chat activity to identify any phishing or suspicious messages sent. Examine the Graph API call logs to see what actions were performed and their timestamps. Correlate with endpoint logs to detect any malware or suspicious processes running on the user's device. Check for signs of account compromise, such as password changes or MFA bypass attempts. Follow further actions done by the account.","investigative_actions": "Verify the user's role and typical usage of Microsoft Graph API. Check if the user's account has recently logged in from unusual locations or devices. Review recent email and chat activity to identify any phishing or suspicious messages sent. Examine the Graph API call logs to see what actions were performed and their timestamps. Correlate with endpoint logs to detect any malware or suspicious processes running on the user's device. Check for signs of account compromise, such as password changes or MFA bypass attempts. Follow further actions done by the account.","name": "User sent messages in Microsoft Teams to multiple conversations via Graph API","name": "User sent messages in Microsoft Teams to multiple conversations via Graph API","required_data": ["required_data": ["Microsoft Graph Logs""Microsoft Graph Logs"],],"severity": "Informational","severity": "Informational","test_period": "1 Hour","test_period": "1 Hour",Show markdown source
@@ -4,17 +4,17 @@ "Lateral Movement (TA0008)" ], "attack_techniques": [ "Internal Spearphishing (T1534)" ], "attackers_goals": "Attackers may leverage a compromised user account to send phishing or malicious messages via Graph API to multiple recipients, aiming to propagate the attack while evading detection.", "deduplication_period": "1 Day", "description": "A user who rarely uses the Graph API for Microsoft Teams messaging sent multiple messages using it.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "Microsoft Teams", "investigative_actions": "Verify the user's role and typical usage of Microsoft Graph API. Check if the user's account has recently logged in from unusual locations or devices. Review recent email and chat activity to identify any phishing or suspicious messages sent. Examine the Graph API call logs to see what actions were performed and their timestamps. Correlate with endpoint logs to detect any malware or suspicious processes running on the user's device. Check for signs of account compromise, such as password changes or MFA bypass attempts. Follow further actions done by the account.", "name": "User sent messages in Microsoft Teams to multiple conversations via Graph API", "required_data": [ "Microsoft Graph Logs" ], "severity": "Informational", "test_period": "1 Hour", -
▸ ▾ User signed in to an application via Power Automate for the first time modified +1 −1
analytics/user-signed-in-to-an-application-via-power-automate-for-the-first-timeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Before After@@ -6,17 +6,17 @@],],"attack_techniques": ["attack_techniques": ["Valid Accounts (T1078)","Valid Accounts (T1078)","Automated Exfiltration (T1020)""Automated Exfiltration (T1020)"],],"attackers_goals": "Use automation flows to automate data exfiltration, C2 communication, lateral movement and evade DLP solutions.","attackers_goals": "Use automation flows to automate data exfiltration, C2 communication, lateral movement and evade DLP solutions.","deduplication_period": "1 Day","deduplication_period": "1 Day","description": "A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account.","description": "A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account.","detection_modules": "Identity Threat Module","detection_modules": "Identity Threat Module, SaaS Threat Detection","detector_tags": "","detector_tags": "","investigative_actions": "Check if this was a desired behavior as part of the automation flow.* Analyze the actions taken by the user during the session and verify that this is a legitimate session. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Look for signs of different data exfiltration via email, shared links or uploads to online storage.","investigative_actions": "Check if this was a desired behavior as part of the automation flow.* Analyze the actions taken by the user during the session and verify that this is a legitimate session. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Look for signs of different data exfiltration via email, shared links or uploads to online storage.","name": "User signed in to an application via Power Automate for the first time","name": "User signed in to an application via Power Automate for the first time","required_data": ["required_data": ["AzureAD""AzureAD"],],"severity": "Informational","severity": "Informational","test_period": "N/A (single event)","test_period": "N/A (single event)",Show markdown source
@@ -6,17 +6,17 @@ ], "attack_techniques": [ "Valid Accounts (T1078)", "Automated Exfiltration (T1020)" ], "attackers_goals": "Use automation flows to automate data exfiltration, C2 communication, lateral movement and evade DLP solutions.", "deduplication_period": "1 Day", "description": "A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account.", - "detection_modules": "Identity Threat Module", + "detection_modules": "Identity Threat Module, SaaS Threat Detection", "detector_tags": "", "investigative_actions": "Check if this was a desired behavior as part of the automation flow.* Analyze the actions taken by the user during the session and verify that this is a legitimate session. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Look for signs of different data exfiltration via email, shared links or uploads to online storage.", "name": "User signed in to an application via Power Automate for the first time", "required_data": [ "AzureAD" ], "severity": "Informational", "test_period": "N/A (single event)",