Tag
Azure AD Authentication from Unexpected Geo-locations
2 rules 1 TTPDetection of successful authentications originating from geographic locations outside of an organization's expected operational footprint, potentially indicating compromised credentials or unauthorized access.
AWS Console Login by User from New City
2 rules 1 TTPDetection of AWS console logins by a user from a previously unseen city, potentially indicating compromised credentials or account takeover.
Azure Service Principal Authentication from Multiple Countries
2 rules 1 TTPDetects Azure service principals authenticating from multiple countries within a short time, indicating potentially compromised credentials being used from different geographic locations.
AWS Account Console Login from Multiple IPs
2 rules 2 TTPsAn AWS account successfully authenticating from multiple unique IP addresses within a 5-minute window may indicate compromised credentials, potentially from a phishing attack.
Geographic Improbable Location Detection
2 rules 1 TTPDetection of user logins originating from geographically distant locations within a short timeframe, indicative of potential Remote Employment Fraud or compromised credentials.