Attempted Azure application access from unknown tenant
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Trusted Relationship (T1199)
Severity
Informational
Description
A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant.
Attacker's Goals
Abuse serverless services to execute code in cloud environments.
Investigative actions
Validate the legitimacy of the tenant in question.
Investigate any unusual activity originating from the application.
Variations
Was this helpful?
