For the complete documentation index, see llms.txt. This page is also available as Markdown.

Successful universal authentication with suspicious features

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Detection Modules

Identity Analytics

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

A universal authentication was flagged as suspicious based on anomalous features.

Attacker's Goals

Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.

Investigative actions

  • Investigate the suspicious authentication.

  • Verify if the ASN is an approved ASN to authenticate from.

  • Follow further actions done by the user.

  • If the IP is associated with a tunnel operator, check whether it is an approved VPN.

Variations

Successful universal authentication sign-in from a TOR exit node

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Medium

Description

A successful sign-in from a TOR exit node in universal authentication.

Attacker's Goals

Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.

Investigative actions

  • Investigate the suspicious authentication.

  • Verify if the ASN is an approved ASN to authenticate from.

  • Follow further actions done by the user.

  • If the IP is associated with a tunnel operator, check whether it is an approved VPN.

Successful universal authentication from a suspicious tunnel operator

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Low

Description

A successful universal authentication was made through a suspicious or rarely seen tunnel operator.

Attacker's Goals

Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.

Investigative actions

  • Investigate the suspicious authentication.

  • Verify if the ASN is an approved ASN to authenticate from.

  • Follow further actions done by the user.

  • If the IP is associated with a tunnel operator, check whether it is an approved VPN.

Suspicious successful universal authentication from ASN

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

A successful universal authentication was made from a suspicious or previously unseen ASN.

Attacker's Goals

Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.

Investigative actions

  • Investigate the suspicious authentication.

  • Verify if the ASN is an approved ASN to authenticate from.

  • Follow further actions done by the user.

  • If the IP is associated with a tunnel operator, check whether it is an approved VPN.

Successful universal authentication from a new country in organization

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

A user authenticated in universal authentication from an unusual country that no one from this organization has connected from before in universal authentication. This may indicate the account was compromised.

Attacker's Goals

Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.

Investigative actions

  • Investigate the suspicious authentication.

  • Verify if the ASN is an approved ASN to authenticate from.

  • Follow further actions done by the user.

  • If the IP is associated with a tunnel operator, check whether it is an approved VPN.

Was this helpful?