A user logged in from an abnormal country or ASN
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006), Resource Development (TA0042)
ATT&CK Technique
Compromise Accounts (T1586), Brute Force: Password Guessing (T1110.001)
Severity
Informational
Description
A user logged in from an unusual country or ASN. This may indicate that the account was compromised.
Attacker's Goals
Gain user-account credentials.
Investigative actions
Check if the user is currently located in the aforementioned country.
Check for any other suspicious activity related to the account.
Check other ASNs and Countries that the user logged in from.
Look for additional login attempts.
Variations
PreviousA user logged in at an unusual time via VPN
NextA user logged in to the AWS console for the first time
Was this helpful?
