Azure application URI modification
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Persistence (TA0003), Lateral Movement (TA0008)
ATT&CK Technique
Account Manipulation (T1098), Use Alternate Authentication Material (T1550)
Severity
Informational
Description
An identity added or updated an Azure application's URI.
Attacker's Goals
An attacker may add certificates or modify authentication methods of an application to authenticate as the application.
Investigative actions
Check whether the account that modified the URI is supposed to perform such actions.
Check for possible logins from the application modified.
Check for possible account consents or credential changes regarding the application.
Follow further actions done by the application.
Variations
Was this helpful?
