A user accessed multiple unusual resources via SSO
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AzureAD OR Azure SignIn Log OR Idira OR Duo OR Okta OR OneLogin OR PingOne
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Discovery (TA0007), Initial Access (TA0001)
ATT&CK Technique
Valid Accounts (T1078), Cloud Service Dashboard (T1538), Cloud Service Discovery (T1526)
Severity
Informational
Description
A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account.
Attacker's Goals
Unusual resources may be accessed for various purposes, including exfiltration, lateral movement, etc.
Investigative actions
Investigate the resources that were accessed to determine if they were used for legitimate purposes or malicious activity.
Variations
Was this helpful?
