First Azure AD PowerShell operation for a user
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Low
Description
A user performed an Azure AD operation using a PowerShell user-agent for the first time.
Attacker's Goals
Achieve initial access to a company's resources.
Investigative actions
Follow the actions the user performed using PowerShell.
Confirm with the user that the action was intended.
PreviousFile transfer from unusual IP using known tools
NextFirst connection from a country in organization
Was this helpful?
