For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure application credentials added

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Persistence (TA0003), Lateral Movement (TA0008)

ATT&CK Technique

Account Manipulation (T1098), Use Alternate Authentication Material (T1550)

Severity

Informational

Description

An identity added credentials to an Azure application.

Attacker's Goals

  • An attacker may add certificates or modify authentication methods of an application to authenticate as the application.

Investigative actions

  • Check if the modified application is new to the organization.

  • Check whether the account that modified the credentials is supposed to perform such actions.

  • Check for possible logins from the application modified.

  • Follow further actions done by the application.

Variations

Suspicious credential operation on an Azure application

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Lateral Movement (TA0008)

ATT&CK Technique

Account Manipulation (T1098), Use Alternate Authentication Material (T1550)

Severity

Medium

Description

An identity added a certificate to an Azure application in a suspicious way.

Attacker's Goals

  • An attacker may add certificates or modify authentication methods of an application to authenticate as the application.

Investigative actions

  • Check if the modified application is new to the organization.

  • Check whether the account that modified the credentials is supposed to perform such actions.

  • Check for possible logins from the application modified.

  • Follow further actions done by the application.

Unusual certificate operation on an Azure application

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Lateral Movement (TA0008)

ATT&CK Technique

Account Manipulation (T1098), Use Alternate Authentication Material (T1550)

Severity

Low

Description

An identity added a certificate to an Azure application with some unusual parameters.

Attacker's Goals

  • An attacker may add certificates or modify authentication methods of an application to authenticate as the application.

Investigative actions

  • Check if the modified application is new to the organization.

  • Check whether the account that modified the credentials is supposed to perform such actions.

  • Check for possible logins from the application modified.

  • Follow further actions done by the application.

Was this helpful?