Granting Access to an Account
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Initial Access (TA0001), Credential Access (TA0006)
ATT&CK Technique
Valid Accounts (T1078), Unsecured Credentials (T1552), Modify Authentication Process (T1556), OS Credential Dumping (T1003), Brute Force (T1110), Forge Web Credentials (T1606)
Severity
Informational
Description
Azure access has been granted to an account.
Attacker's Goals
Gain unauthorized access to an account.* Gain access to sensitive data.
Investigative actions
Check the account access logs to determine the source of the access.* Check the account activity logs to determine the purpose of the access.
PreviousGoogle Workspace user authentication information changed
NextHidden Attribute was added to a file using attrib.exe
Was this helpful?
