For the complete documentation index, see llms.txt. This page is also available as Markdown.

First SSO Resource Access in the Organization

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: AzureAD OR Azure SignIn Log OR Idira OR Duo OR Okta OR OneLogin OR PingOne

Detection Modules

Identity Analytics

ATT&CK Tactic

Initial Access (TA0001), Discovery (TA0007)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002), Cloud Service Discovery (T1526)

Severity

Informational

Description

A resource was accessed for the first time via SSO.

Attacker's Goals

Use a possibly compromised account to access privileged resources.

Investigative actions

  • Confirm that the activity is benign (e.g. this is a newly approved resource).

  • Follow further actions done by the user that attempted to access the resource.

Variations

Abnormal first access to a resource via SSO in the organization

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001), Discovery (TA0007)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002), Cloud Service Discovery (T1526)

Severity

Low

Description

A resource was accessed for the first time via SSO with suspicious characteristics.

Attacker's Goals

Use a possibly compromised account to access privileged resources.

Investigative actions

  • Confirm that the activity is benign (e.g. this is a newly approved resource).

  • Follow further actions done by the user that attempted to access the resource.

Was this helpful?