SaaS suspicious external domain user activity
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Google Workspace Audit Logs OR Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
External Remote Services (T1133)
Severity
Informational
Description
An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.
Attacker's Goals
Gain their initial foothold within the organization and explore the environment to achieve their target.
Investigative actions
Investigate the external domain name.
Check the identity activity in the organization.
Variations
PreviousSAAS - Email was reported by the user or administrator as a phishing attempt
NextSCCM log files enumeration
Was this helpful?
