Tag
medium
advisory
Google Workspace User Sign-in from Atypical Device Type
2 rules 2 TTPsThis rule detects when a Google Workspace user authenticates from a device type that hasn't been observed for that user in the past 14 days, potentially indicating account compromise via AiTM kits or stolen OAuth refresh tokens.
Google Workspace
google_workspace
persistence
account_compromise
device_registration
2r
2t
medium
advisory
AWS Console Login by User from New Region
2 rules 1 TTPAn AWS account may be compromised if a user logs into the AWS console from a geographic region they have never accessed before, potentially indicating unauthorized access or account takeover.
AWS Management Console
cloud
aws
iam
account_compromise
2r
1t
high
advisory
Azure AD Sign-In with Unfamiliar Properties
2 rules 4 TTPsThis alert detects Azure AD sign-ins with properties unfamiliar to the user, indicating potential account compromise or unauthorized access.
Azure Active Directory
azure
identity_protection
sign-in
account_compromise
risk_detection
2r
4t
high
advisory
O365 Email Account Compromise via Excessive Hard Deletes
1 rule 2 TTPsCompromised O365 accounts may perform excessive email hard deletes within an hour to remove evidence of malicious activity, potentially indicating account takeover.
Office 365
o365
email
account_compromise
data_destruction
1r
2t