Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0007 — Web Credential Usage
DC0007

Web Credential Usage

20 analytic(s) · 6 detection strategy(ies)

Description

An attempt by a user to gain access to a network or computing resource by providing web credentials (ex: Windows EID 1202)

Referenced in Analytics

20
AN0201 Analytic 0201 DET0074

Anomalous access to cloud web applications using session tokens without corresponding MFA/credential validation, often from unusual locations or device fingerprints.

AWS:CloudTrail AWS:CloudTrail
AN0202 Analytic 0202 DET0074

Session cookie reuse on unmanaged browsers, devices, or client types deviating from user baseline (e.g., switching from Chrome to curl).

m365:unified saas:okta
AN0419 Analytic 0419 DET0148

Forged SAML tokens in IaaS environments often manifest as cross-cloud or cross-account authentication without matching STS events. Defenders may see AssumeRole or GetFederationToken API usage without a corresponding SAML assertion log from the trusted IdP.

AWS:CloudTrail CloudTrail:Signin
AN0421 Analytic 0421 DET0148

Forged SAML tokens can appear as SaaS logins where authentication succeeded without MFA, or where tokens contain claims inconsistent with the user profile. Look for concurrent sessions across different geographies with the same SAML assertion ID.

saas:access m365:unified
AN0422 Analytic 0422 DET0148

Forged SAML tokens may be leveraged to access O365 apps such as Outlook or SharePoint. Defenders should monitor for token replay across multiple clients or access attempts to privileged mailboxes without prior interactive login.

m365:exchange m365:sharepoint
AN0483 Analytic 0483 DET0171

Forged cookies in IaaS environments may appear as authentication attempts that bypass MFA, leveraging AssumeRole or session APIs with cookies that were never legitimately issued. Defenders should correlate cloud logs for cookie-based sessions without prior valid authentication, often followed by resource access from unfamiliar IP addresses.

AWS:CloudTrail AWS:CloudTrail
AN0486 Analytic 0486 DET0171

Forged cookies on macOS may show up as abnormal access to Safari/Chrome cookie databases in ~/Library/Cookies, combined with unexpected logon sessions authenticated by those cookies. Unified Logs may show cookie injection events or abnormal access patterns to Keychain when linked to browser authentication flows.

macos:unifiedlog macos:unifiedlog
AN0487 Analytic 0487 DET0171

Forged cookies in SaaS environments manifest as valid web sessions without matching login activity, MFA enforcement bypass, or cookies reused across multiple devices/IPs. Defenders should look for cookie replay, concurrent sessions from multiple geographies, or session tokens generated by unrecognized apps.

m365:unified saas:access
AN0526 Analytic 0526 DET0185

Use of AWS STS or GCP IAM APIs to request temporary tokens or federation sessions inconsistent with normal account activity, including from unexpected principals or regions.

AWS:CloudTrail AWS:CloudTrail
AN0527 Analytic 0527 DET0185

OAuth or SAML access tokens reused across multiple sessions or clients without corresponding MFA or login activity.

azure:signinlogs m365:unified
AN0528 Analytic 0528 DET0185

Application access tokens used to call APIs (e.g., Google Workspace, Salesforce) without interactive logins, often with unusual scopes or elevated permissions.

saas:googleworkspace saas:salesforce
AN0529 Analytic 0529 DET0185

OAuth token usage for Exchange Online or SharePoint API access without preceding login or from unauthorized clients.

m365:unified
AN0530 Analytic 0530 DET0185

Compromised service account tokens mounted inside containers and reused for external API calls or lateral movement across services.

kubernetes:apiserver AWS:CloudTrail
AN0718 Analytic 0718 DET0260

Forged web credentials may manifest as anomalous SAML token issuance, OpenID Connect token minting, or Zimbra pre-auth key usage. Defenders may see tokens issued without normal authentication events, multiple valid tokens generated simultaneously, or signing anomalies in IdP logs.

azure:signinlogs NSM:Connections
AN0721 Analytic 0721 DET0260

Forged credentials on macOS may be visible through Unified Logs showing abnormal access to Keychain or browser session files. Correlated with anomalous web session usage from Safari or Chrome processes outside typical user context.

macos:unifiedlog macos:unifiedlog
AN0722 Analytic 0722 DET0260

SaaS platforms may show forged credentials as unusual API keys, tokens, or session cookies being used without corresponding authentication. Correlated patterns include simultaneous valid sessions from multiple geographies, unusual API calls with new tokens, or bypass of expected MFA enforcement.

m365:unified saas:auth
AN0956 Analytic 0956 DET0338

Token replay or impersonation in federated logins without interactive browser session or MFA prompts.

azure:signinlogs m365:unified
AN0957 Analytic 0957 DET0338

Unusual reuse of OAuth access tokens from different geographic regions, without full login events.

saas:googleworkspace saas:googleworkspace
AN0959 Analytic 0959 DET0338

Access token reuse to connect to SharePoint or Outlook APIs without interactive user context.

m365:unified
AN0960 Analytic 0960 DET0338

Use of instance metadata tokens across instances or misuse of short-lived tokens issued for different roles.

AWS:CloudTrail AWS:CloudTrail

Details

MITRE ID
DC0007
STIX ID
x-mitre-data-component--ff93f688-d7a4-49cf-9c79-a14454da8428
Analytics
20
Detection Strategies
6
Leaving Threaticon

This link opens an external site that isn't part of the platform.