Product
CVE-2026-23663: Azure Entra ID Improper Privilege Management Vulnerability
2 rules 1 TTP 1 CVECVE-2026-23663 is a privilege escalation vulnerability in Azure Entra ID that allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-40379 Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability
2 rules 1 TTPCVE-2026-40379 is a spoofing vulnerability in Microsoft Enterprise Security Token Service (ESTS) where exposure of sensitive information in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
Azure Entra ID MFA TOTP Brute Force Attempted
3 rules 1 TTPIdentifies brute force attempts against Azure Entra multi-factor authentication (MFA) Time-based One-Time Password (TOTP) verification codes, characterized by high-frequency failed attempts for a single user across numerous distinct sessions, potentially indicating programmatic attempts to bypass MFA.
Entra ID Concurrent Sign-in with Suspicious Properties
2 rules 4 TTPsThis rule identifies concurrent Azure sign-in events for the same user from multiple sources, where at least one authentication event exhibits suspicious properties associated with DeviceCode and OAuth phishing, potentially indicating refresh token theft.
Entra ID User Sign-in with Unusual Authentication Type
2 rules 4 TTPsDetects rare authentication requirements for Azure Entra ID principal users, potentially indicating an adversary attempting to bypass conditional access policies and MFA using stolen credentials.