Azure account creation by a non-standard account
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation (T1098), Create Account (T1136)
Severity
Informational
Description
An Azure AD account creation was performed by a user that doesn't typically create users.
Attacker's Goals
Create a backdoor account for later access to Azure AD or Azure resources, or delete evidence of such an account.
Investigative actions
Follow further actions by the initiator.
Check for new resource creations by the new user.
Check if the new user was added to a privileged role.
Follow further actions done by the new user.
Variations
Was this helpful?
