open-menu
closeme
Microsoft Azure or Mail Sign-in from a Suspicious Source
calendar
May 6, 2025
·
Domain: Cloud
Domain: SaaS
Data Source: Azure
Data Source: Entra ID
Data Source: Entra ID Sign-in Logs
Data Source: Microsoft 365
Data Source: Microsoft 365 Audit Logs
Use Case: Identity and Access Audit
Use Case: Threat Detection
Tactic: Initial Access
Resources: Investigation Guide
Rule Type: Higher-Order Rule
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Activity via Auth Broker On-Behalf-of Principal User
calendar
May 6, 2025
·
Domain: Cloud
Data Source: Azure
Data Source: Entra ID
Data Source: Entra ID Sign-in Logs
Use Case: Identity and Access Audit
Use Case: Threat Detection
Resources: Investigation Guide
Tactic: Defense Evasion
Tactic: Persistence
·
Share on:
twitter
facebook
linkedin
copy
to-top