Successful universal authentication with suspicious features
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Detection Modules
Identity Analytics
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
A universal authentication was flagged as suspicious based on anomalous features.
Attacker's Goals
Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.
Investigative actions
Investigate the suspicious authentication.
Verify if the ASN is an approved ASN to authenticate from.
Follow further actions done by the user.
If the IP is associated with a tunnel operator, check whether it is an approved VPN.
Variations
Was this helpful?
