EXPLORE

EXPLORE DETECTIONS

🔍
3,270 detections found

AWS Successful Console Login Without MFA

Detects successful AWS console logins that were performed without Multi-Factor Authentication (MFA). This alert can be used to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.

T1078.004
Sigmamedium

AWS Suspicious SAML Activity

Identifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.

T1078T1548T1550T1550.001
Sigmamedium

AWS User Login Profile Was Modified

Detects activity when someone is changing passwords on behalf of other users. An attacker with the "iam:UpdateLoginProfile" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.

T1098
Sigmahigh

AWS VPC Flow Logs Deleted

Detects the deletion of one or more VPC Flow Logs in AWS Elastic Compute Cloud (EC2) through the DeleteFlowLogs API call. Adversaries may delete flow logs to evade detection or remove evidence of network activity, hindering forensic investigations and visibility into malicious operations.

Sigmahigh

Azure Active Directory Hybrid Health AD FS New Server

This detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server. This can be done programmatically via HTTP requests to Azure.

T1578
Sigmamedium

Azure Active Directory Hybrid Health AD FS Service Delete

This detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant. A threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs. The health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.

T1578.003
Sigmamedium

Azure AD Account Credential Leaked

Indicates that the user's valid credentials have been leaked.

T1589
Sigmahigh

Azure AD Health Monitoring Agent Registry Keys Access

This detection uses Windows security events to detect suspicious access attempts to the registry key of Azure AD Health monitoring agent. This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object HKLM\SOFTWARE\Microsoft\Microsoft Online\Reporting\MonitoringAgent.

T1012
Sigmamedium

Azure AD Health Service Agents Registry Keys Access

This detection uses Windows security events to detect suspicious access attempts to the registry key values and sub-keys of Azure AD Health service agents (e.g AD FS). Information from AD Health service agents can be used to potentially abuse some of the features provided by those services in the cloud (e.g. Federation). This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object: HKLM:\SOFTWARE\Microsoft\ADHealthAgent. Make sure you set the SACL to propagate to its sub-keys.

T1012
Sigmamedium

Azure AD Only Single Factor Authentication Required

Detect when users are authenticating without MFA being required.

T1078.004T1556.006
Sigmalow

Azure AD Threat Intelligence

Indicates user activity that is unusual for the user or consistent with known attack patterns.

T1078
Sigmahigh

Azure Application Deleted

Identifies when a application is deleted in Azure.

T1489
Sigmamedium

Azure Application Gateway Modified or Deleted

Identifies when a application gateway is modified or deleted.

Sigmamedium

Azure Application Security Group Modified or Deleted

Identifies when a application security group is modified or deleted.

Sigmamedium

Azure Container Registry Created or Deleted

Detects when a Container Registry is created or deleted.

T1485T1496T1489
Sigmalow

Azure Device No Longer Managed or Compliant

Identifies when a device in azure is no longer managed or compliant

Sigmamedium

Azure Device or Configuration Modified or Deleted

Identifies when a device or device configuration in azure is modified or deleted.

T1485T1565.001
Sigmamedium

Azure DNS Zone Modified or Deleted

Identifies when DNS zone is modified or deleted.

T1565.001
Sigmamedium

Azure Domain Federation Settings Modified

Identifies when an user or application modified the federation settings on the domain.

T1078
Sigmamedium

Azure Firewall Modified or Deleted

Identifies when a firewall is created, modified, or deleted.

T1686.001
Sigmamedium

Azure Firewall Rule Collection Modified or Deleted

Identifies when Rule Collections (Application, NAT, and Network) is being modified or deleted.

T1686.001
Sigmamedium

Azure Firewall Rule Configuration Modified or Deleted

Identifies when a Firewall Rule Configuration is Modified or Deleted.

Sigmamedium

Azure Key Vault Modified or Deleted

Identifies when a key vault is modified or deleted.

T1552T1552.001
Sigmamedium

Azure Keyvault Key Modified or Deleted

Identifies when a Keyvault Key is modified or deleted in Azure.

T1552T1552.001
Sigmamedium
PreviousPage 9 of 137Next