Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0006 — Web Credential Creation
DC0006

Web Credential Creation

5 analytic(s) · 2 detection strategy(ies)

Description

Initial construction of new web credential material (ex: Windows EID 1200 or 4769)

Referenced in Analytics

5
AN0420 Analytic 0420 DET0148

Forged SAML tokens may be used on Windows systems to authenticate to federated apps without normal Kerberos activity. Defenders may detect anomalous event correlation, where access to SaaS/O365 via SAML occurs without prior TGT requests or user logons.

WinEventLog:Security WinEventLog:ADFS
AN0717 Analytic 0717 DET0260

Defenders may detect adversaries forging web credentials in IaaS environments by monitoring for anomalous API activity such as AssumeRole or GetFederationToken being executed by unusual principals. These events often correlate with sudden logon sessions from unfamiliar IP addresses or regions. The chain is usually secret material misuse (stolen private key or password) → API request generating a new token → access to high-value resources.

AWS:CloudTrail AWS:CloudTrail
AN0718 Analytic 0718 DET0260

Forged web credentials may manifest as anomalous SAML token issuance, OpenID Connect token minting, or Zimbra pre-auth key usage. Defenders may see tokens issued without normal authentication events, multiple valid tokens generated simultaneously, or signing anomalies in IdP logs.

azure:signinlogs NSM:Connections
AN0722 Analytic 0722 DET0260

SaaS platforms may show forged credentials as unusual API keys, tokens, or session cookies being used without corresponding authentication. Correlated patterns include simultaneous valid sessions from multiple geographies, unusual API calls with new tokens, or bypass of expected MFA enforcement.

m365:unified saas:auth
AN0723 Analytic 0723 DET0260

Forged web credentials in Office Suite contexts may appear as abnormal authentication headers in Outlook or Teams traffic, or unexplained OAuth grants in M365/Azure logs. Defenders should correlate token usage events with missing authentication flows and mismatched device/user context.

m365:oauth m365:signinlogs

Details

MITRE ID
DC0006
STIX ID
x-mitre-data-component--5f7c9def-0ddf-423b-b1f8-fb2ddeed0ce3
Analytics
5
Detection Strategies
2
Leaving Threaticon

This link opens an external site that isn't part of the platform.