For the complete documentation index, see llms.txt. This page is also available as Markdown.

Attempted Azure application access from unknown tenant

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs

Detection Modules

Cloud

Detector Tags

Microsoft Graph Activity Logs

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Trusted Relationship (T1199)

Severity

Informational

Description

A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant.

Attacker's Goals

Abuse serverless services to execute code in cloud environments.

Investigative actions

  • Validate the legitimacy of the tenant in question.

  • Investigate any unusual activity originating from the application.

Variations

Attempted Azure application access from an unusual tenant

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Trusted Relationship (T1199)

Severity

Medium

Description

A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant.

Attacker's Goals

Abuse serverless services to execute code in cloud environments.

Investigative actions

  • Validate the legitimacy of the tenant in question.

  • Investigate any unusual activity originating from the application.

Azure application access from unknown tenant

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Trusted Relationship (T1199)

Severity

Low

Description

A Microsoft Graph API was executed by an Azure application from an unknown tenant.

Attacker's Goals

Abuse serverless services to execute code in cloud environments.

Investigative actions

  • Validate the legitimacy of the tenant in question.

  • Investigate any unusual activity originating from the application.

Was this helpful?