For the complete documentation index, see llms.txt. This page is also available as Markdown.

SSO authentication by a service account

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

2 Days

Required Data

Requires one of the following data sources: AzureAD OR Azure SignIn Log OR Idira OR Duo OR Okta OR OneLogin OR PingOne

Detection Modules

Identity Analytics

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002)

Severity

Low

Description

A service account successfully authenticated via SSO.

Attacker's Goals

Use an account that has access to resources to move laterally in the network and access privileged resources.

Investigative actions

  • Check whether the account has done any administrative actions it should not usually do.

  • Look for more logins and authentications by the account throughout the network.

Variations

Rare non-interactive SSO authentication by a service account

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002)

Severity

Informational

Description

A service account successfully authenticated via SSO.

Attacker's Goals

Use an account that has access to resources to move laterally in the network and access privileged resources.

Investigative actions

  • Check whether the account has done any administrative actions it should not usually do.

  • Look for more logins and authentications by the account throughout the network.

SSO authentication by a service account via a suspicious IP

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002)

Severity

Low

Description

A service account successfully authenticated via SSO.

Attacker's Goals

Use an account that has access to resources to move laterally in the network and access privileged resources.

Investigative actions

  • Check whether the account has done any administrative actions it should not usually do.

  • Look for more logins and authentications by the account throughout the network.

First time SSO authentication by a service account

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002)

Severity

Medium

Description

A service account successfully authenticated via SSO for the first time over the past 30 days.

Attacker's Goals

Use an account that has access to resources to move laterally in the network and access privileged resources.

Investigative actions

  • Check whether the account has done any administrative actions it should not usually do.

  • Look for more logins and authentications by the account throughout the network.

Was this helpful?