For the complete documentation index, see llms.txt. This page is also available as Markdown.

Granting Access to an Account

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Azure Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Initial Access (TA0001), Credential Access (TA0006)

ATT&CK Technique

Valid Accounts (T1078), Unsecured Credentials (T1552), Modify Authentication Process (T1556), OS Credential Dumping (T1003), Brute Force (T1110), Forge Web Credentials (T1606)

Severity

Informational

Description

Azure access has been granted to an account.

Attacker's Goals

  • Gain unauthorized access to an account.* Gain access to sensitive data.

Investigative actions

  • Check the account access logs to determine the source of the access.* Check the account activity logs to determine the purpose of the access.

Was this helpful?