Suspicious Azure AD interactive sign-in using PowerShell
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD
Detection Modules
Identity Analytics
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
A user interactively logged in to Azure AD via PowerShell.
Attacker's Goals
The attacker attempts to gain access to the organization's resources.
Investigative actions
Analyze the actions taken by the user during the session and verify that this is a legitimate session.
Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Variations
Was this helpful?
