Tag
Azure AD User ImmutableId Attribute Modification for Persistence
2 rules 1 TTPThe following analytic identifies modifications to the SourceAnchor (ImmutableId) attribute for an Azure Active Directory user, which is a step in setting up an Azure AD identity federation backdoor that allows an attacker to impersonate any user and bypass MFA.
Fleet Windows MDM Azure AD JWT Authentication Bypass Vulnerability
2 rules 2 TTPs 1 IOCA vulnerability in Fleet versions prior to 4.82.0 allows authentication tokens from any Azure AD tenant to be accepted, enabling unauthorized device enrollment and MDM API access due to improper JWT signature validation, tracked as CVE-2026-24899.
O365 Admin Consent Bypassed by Service Principal
2 rules 2 TTPsA service principal in Office 365 Azure Active Directory assigns app roles without standard admin consent, potentially bypassing critical administrative controls and leading to unauthorized access or privilege escalation.
Azure AD Authentication from Unexpected Geo-locations
2 rules 1 TTPDetection of successful authentications originating from geographic locations outside of an organization's expected operational footprint, potentially indicating compromised credentials or unauthorized access.
Azure AD Privileged Graph API Permission Assignment
2 rules 1 TTPDetection of high-risk Graph API permission assignments (Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, and RoleManagement.ReadWrite.Directory) in Azure AD, potentially leading to unauthorized modifications and security breaches.
Azure AD FullAccessAsApp Permission Assignment
2 rules 2 TTPsDetection of 'full_access_as_app' permission assignment to an application in Office 365 Exchange Online, potentially leading to unauthorized access and data exfiltration.
Azure AD Threat Intelligence Detection
2 rules 1 TTPThis brief focuses on detecting unusual user activity and sign-in patterns flagged by Azure AD Threat Intelligence, which may indicate stealthy attacks, persistence attempts, privilege escalation, or initial access.
Entra ID Service Principal Federated Issuer Modification
2 rules 1 TTPEntra ID (Azure AD) service principal federated issuers can be modified by an attacker to establish persistence within a target environment.
BloodHound Suite User-Agent Detected in Entra ID Sign-ins
3 rules 6 TTPsDetection of BloodHound tools like AzureHound and SharpHound being used to enumerate Microsoft Entra ID and Microsoft 365 environments, potentially indicating reconnaissance activity by red teams or malicious actors.
Azure AD Activity From Anonymous IP Address
2 rules 4 TTPsDetection of user activity originating from an IP address identified as an anonymous proxy, potentially indicating unauthorized access, privilege escalation, or persistence within an Azure Active Directory environment.
Azure AD Service Principal Enumeration via Microsoft Graph API
2 rules 2 TTPsAn attacker uses Microsoft Graph API to enumerate multiple Azure AD service principals, potentially using tools like AzureHound or ROADtools, to gather information for privilege escalation or lateral movement.
AzureHound Reconnaissance Activity in Azure AD
2 rules 2 TTPsDetection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.
Azure AD User Added to Global or Device Admin Role
2 rules 3 TTPsAn attacker may attempt to add a user to a high-privilege Azure AD role, such as Global Administrator or Device Administrator, to establish persistence, gain initial access, escalate privileges, or operate stealthily within the compromised environment.
Azure AD Password Spraying Attack Detection
2 rules 3 TTPsA single source IP failing to authenticate with multiple valid users in Azure AD, potentially indicating a Password Spraying attack, is detected using Azure SignInLogs and the 3-sigma rule to identify anomalous failed login patterns.
Azure AD Account Concurrent Sessions from Different IPs
2 rules 1 TTPDetection of Azure AD accounts with concurrent sessions originating from multiple unique IP addresses within a 5-minute window, potentially indicating session hijacking and unauthorized access.
Azure AD Temporary Access Pass Added to Account
2 rules 4 TTPsDetection of a temporary access pass (TAP) being added to an Azure AD account, which could indicate potential privilege escalation, initial access, persistence, or stealth activity.
O365 Service Principal Creation Detection
2 rules 1 TTPDetection of new service principal creation in O365 tenants, which can be abused by attackers for unauthorized access, API interaction, and data compromise.
O365 Risk-Based Consent Disabled
2 rules 1 TTPThe disabling of the 'risk-based step-up consent' security setting in Microsoft 365 allows users to grant consent to potentially malicious applications, increasing the risk of OAuth phishing and unauthorized access to sensitive data.
O365 Application Registration Owner Added
3 rules 1 TTPA new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.
O365 Application Available To Other Tenants
2 rules 1 TTPAn Azure Active Directory Application is configured to allow authentication from external tenants or personal accounts, potentially leading to unauthorized access to data or capabilities.
O365 Add App Role Assignment Grant User
2 rules 1 TTPThis analytic detects the addition of an application role assignment grant to a user in Office 365, which can indicate unauthorized privilege escalation or the assignment of sensitive roles, leading to unauthorized access within the Office 365 environment.
Microsoft 365 Risk-Based Step-Up Consent Disabled
2 rules 1 TTPThe Microsoft 365 'risk-based step-up consent' security setting is disabled by an adversary to allow users to grant consent to malicious applications, potentially leading to unauthorized access and data breaches.
Detection of Privileged Azure AD Role Assignment
2 rules 2 TTPsDetection of privileged Azure AD role assignments to users, which can indicate persistence and privilege escalation by threat actors.
Azure AD User ImmutableId Attribute Modification for Persistence
2 rules 1 TTPAttackers modify the ImmutableID attribute of an Azure AD user to establish a federation backdoor, bypassing MFA and enabling persistent access.
Azure AD User Consent Blocked for Risky Application
2 rules 1 TTPAzure AD blocked a user's attempt to grant consent to a risky application, indicating potential OAuth abuse and requiring investigation of the user and application involved.
Azure AD Successful Single-Factor Authentication
2 rules 2 TTPsSuccessful single-factor authentication events against Azure Active Directory are identified using Azure SignInLogs data, which may indicate misconfiguration, policy violation, or potential account takeover leading to data breaches and privilege escalation.
Azure AD Service Principal Credential Addition
2 rules 2 TTPsDetection of new credentials added to Azure AD Service Principals and Applications via monitoring of the 'Update application*Certificates and secrets management' operation, potentially indicating persistence or privilege escalation attempts.
Azure AD Service Principal Authentication Monitoring
2 rules 1 TTPThis analytic identifies authentication events of service principals in Azure Active Directory, monitoring sign-in frequency, timing, source IPs, and accessed resources to detect potential anomalies indicative of compromised credentials or malicious activities.
Azure AD Privileged Authentication Administrator Role Assignment Detected
2 rules 2 TTPsAn adversary assigning the 'Privileged Authentication Administrator' role to an account in Azure AD could abuse the new privileges to reset authentication methods for privileged accounts, leading to account takeover and privilege escalation.
Azure AD Multiple Denied MFA Requests Indicating Potential Account Compromise
2 rules 2 TTPsDetection of an unusually high number of denied MFA requests for a single user within a short timeframe in Azure AD, potentially indicating a targeted account compromise attempt.
Azure AD Multiple AppIDs and UserAgents Authentication Spike
2 rules 2 TTPsDetects anomalous Azure AD authentication activity characterized by a single user exceeding 8 authentication attempts, utilizing 3+ unique application IDs and 5+ unique user agents within a 5-minute window, potentially indicating MFA probing or account compromise.
Azure AD MFA Fatigue Attack
2 rules 2 TTPsAn attacker attempts to bypass multi-factor authentication by flooding a user with MFA requests, potentially leading to account compromise.
Azure AD High-Risk Sign-in Detection
2 rules 3 TTPsDetection of high-risk Azure Active Directory sign-in attempts, identified by Azure Identity Protection, indicating potentially compromised accounts and unauthorized access to sensitive resources.
Azure AD Federated Domain Added
2 rules 1 TTPThis analytic detects the addition of a new federated domain within an Azure Active Directory tenant, potentially indicating the establishment of an Azure AD identity federation backdoor for persistence and unauthorized access.
Azure AD Device Code Phishing Attack Detection
2 rules 2 TTPsThis brief details the detection of Azure AD Device Code Phishing attacks, where attackers bypass MFA and Conditional Access Policies (CAPs) to gain unauthorized access to Azure AD resources by abusing the device code authentication protocol.
Azure AD Custom Domain Addition for Persistence
2 rules 1 TTPDetection of a new custom domain addition in Azure AD audit logs, potentially indicating an attacker establishing persistence via identity federation backdoors for unauthorized access and privilege escalation.
Azure AD Authentication Failed During MFA Challenge
3 rules 3 TTPsDetection of failed authentication attempts against an Azure AD tenant during the MFA challenge, specifically flagged by error code 500121, leveraging Azure AD SignInLogs, which may indicate an adversary attempting to authenticate using compromised credentials on an account with MFA enabled, potentially leading to unauthorized access.
Azure AD Application Administrator Role Assigned to User
2 rules 1 TTPAn adversary may assign the Azure AD Application Administrator role to a user account for privilege escalation and application credential management, potentially leading to sensitive resource access and tenant compromise.
Azure AD Admin Consent Bypassed by Service Principal
2 rules 1 TTPA service principal in Azure Active Directory is assigning app roles without standard admin consent, potentially leading to unauthorized privilege escalation by exploiting automation to assign sensitive permissions without proper oversight.
Azure AD Account Enabled and Password Reset for Backdoor
2 rules 1 TTPDetection of an Azure AD user enabling a disabled account and immediately resetting the password, indicating a potential backdoor being established by an adversary with administrative access.
Azure AD PowerShell Authentication Abuse
2 rules 2 TTPsAdversaries may compromise accounts and leverage successful PowerShell authentication in Azure AD to enumerate cloud resources, escalate privileges, and further exploit the Azure environment.
Azure AD Global Administrator Role Assigned
2 rules 2 TTPsDetection of Azure AD Global Administrator role assignment to a user, potentially leading to privilege escalation and control over Azure resources.
Azure AD External Guest User Invitation
2 rules 1 TTPDetection of an external guest user invitation in Azure AD through monitoring Azure AD AuditLogs, which, if malicious, can lead to unauthorized access, data breaches, or further exploitation by abusing external identities.
Azure AD Failed Authentication Increase
2 rules 1 TTPDetects a significant increase (10% or greater) in failed Azure AD sign-in attempts, potentially indicating brute-force attacks, credential stuffing, or other unauthorized access attempts.
Unauthorized Guest User Invitations in Azure AD
2 rules 3 TTPsDetection of unauthorized guest user invitations within an Azure Active Directory tenant, indicating potential privilege escalation, persistence, or initial access attempts.
O365 Cross-Tenant Access Policy Changes
2 rules 2 TTPsAdversaries modify Azure Active Directory cross-tenant access policies for lateral movement or persistence within compromised Microsoft 365 environments.
Impossible Travel Detection in Azure AD
2 rules 1 TTPThis brief describes the detection of 'impossible travel' events in Azure AD, where a user appears to log in from geographically distant locations within an implausibly short time frame, potentially indicating account compromise.
Azure AD Brute Force Attack Detected via High Failed Authentication Count
2 rules 1 TTPDetection of a potential brute-force attack against an Azure AD account, identified by a high number of failed authentication attempts within a short time frame, potentially leading to unauthorized access and data breaches.