Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0002 — User Account Authentication
DC0002

User Account Authentication

109 analytic(s) · 54 detection strategy(ies)

Description

An attempt (successful and failed login attempts) by a user, service, or application to gain access to a network, system, or cloud-based resource. This typically involves credentials such as passwords, tokens, multi-factor authentication (MFA), or biometric validation.

Referenced in Analytics

109
AN0007 Analytic 0007 DET0003

Adversary with access to domain management tools (e.g., `realmd`, `samba-tool`, `ldapmodify`) creates a new domain user via command-line utilities. Behavior chain: LDAP command or script triggers → user entry added in AD via Kerberos/LDAP traffic.

auditd:SYSCALL NSM:Flow
AN0147 Analytic 0147 DET0054

Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.

WinEventLog:Security WinEventLog:Security WinEventLog:Security m365:unified WinEventLog:Sysmon
AN0202 Analytic 0202 DET0074

Session cookie reuse on unmanaged browsers, devices, or client types deviating from user baseline (e.g., switching from Chrome to curl).

m365:unified saas:okta
AN0215 Analytic 0215 DET0078

Detects adversarial use of cloud APIs for command execution, resource control, or reconnaissance. Focuses on CLI/SDK/scripting language abuse via stolen credentials or in-browser Cloud Shells. Monitors for anomalous API calls chained with authentication context shifts (e.g., stolen token -> privileged action) and cross-service impacts.

AWS:CloudTrail azure:activity Okta:SystemLog
AN0295 Analytic 0295 DET0105

Sudden valid logins from accounts that previously had credentials dumped but had not authenticated successfully in the past; correlated with timeline of suspected hash cracking

azure:signinlogs
AN0296 Analytic 0296 DET0105

Offline cracking inferred by subsequent successful CLI or web-based authentications into routers or switches from previously dumped accounts

networkdevice:syslog
AN0305 Analytic 0305 DET0108

ESXi daemons (e.g., hostd, vpxa) are wrapped or impersonated to send large outbound traffic using gzip/Base64 encoding over SSH or HTTP. These actions follow suspicious logins or shell access.

esxi:shell esxi:vmkernel ESXiLogs:authlog
AN0310 Analytic 0310 DET0111

Detection monitors SaaS collaboration tools (e.g., Slack, Zoom, Jira) for messages or files containing credential-like patterns, or for suspicious API calls retrieving bulk chat histories by non-admin users. Identifies adversary behavior chains where chat logs are queried via APIs or integration bots to systematically extract sensitive material.

saas:slack saas:okta
AN0335 Analytic 0335 DET0120

Password changes or account deletions via 'passwd', 'userdel', or 'chage' preceded by interactive shell or remote command execution from non-privileged accounts.

auditd:SYSCALL NSM:Connections
AN0336 Analytic 0336 DET0120

Execution of dscl or sysadminctl commands to disable, delete, or modify users combined with anomalous process ancestry or terminal session launch.

macos:unifiedlog macos:unifiedlog
AN0337 Analytic 0337 DET0120

Invocation of esxcli 'system account remove' from vCLI, SSH, or vSphere API with anomalous user access or outside maintenance windows.

esxi:hostd esxi:vpxa
AN0338 Analytic 0338 DET0120

O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass.

m365:unified m365:signinlogs
AN0387 Analytic 0387 DET0137

Execution of destructive CLI commands such as 'erase startup-config', 'erase flash:' or 'format disk' on routers/switches. Detect privilege level escalation preceding destructive commands.

networkdevice:cli networkdevice:syslog
AN0399 Analytic 0399 DET0142

Detects unauthorized or anomalous use of command-line interfaces (CLI) on network devices. Focuses on remote access sessions (e.g., SSH/Telnet), privilege escalation within CLI sessions, execution of high-risk commands (e.g., config replace, terminal monitor, no logging), and configuration changes outside of approved windows.

networkdevice:syslog NSM:Flow networkdevice:syslog
AN0418 Analytic 0418 DET0148

Forged SAML tokens can be observed as authentication attempts with valid signatures but missing expected preceding Kerberos or authentication events. Defenders may correlate SAML assertions with absent Event IDs 4769, 1200, or 1202, or tokens issued with abnormal lifetimes, issuers, or claims compared to baseline.

azure:signinlogs WinEventLog:Security
AN0431 Analytic 0431 DET0151

A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic.

auditd:SYSCALL auditd:SYSCALL linux:syslog linux:cron
AN0443 Analytic 0443 DET0156

Automated and repetitive triggering of SMS messages through OTP/account verification fields on SaaS platforms, leveraging background messaging APIs such as Twilio, AWS SNS, or Amazon Cognito to generate traffic toward attacker-controlled numbers.

saas:application saas:audit
AN0449 Analytic 0449 DET0160

Monitor for excessive or anomalous MFA push notifications or token requests, especially when login attempts originate from unusual IPs or geolocations and do not correspond to legitimate user-initiated sessions.

azure:signinlogs NSM:Connections
AN0450 Analytic 0450 DET0160

Detect abnormal MFA activity within cloud service provider logs, such as repeated generation of MFA challenges for the same user session or mismatched MFA device and login origin.

AWS:CloudTrail
AN0451 Analytic 0451 DET0160

Detect repeated failed login events followed by MFA challenges triggered in rapid succession, especially if originating from service accounts or anomalous IP addresses.

WinEventLog:Security
AN0452 Analytic 0452 DET0160

Monitor PAM and syslog entries for unusual frequency of login attempts that trigger MFA prompts, particularly when MFA challenges do not match expected user behavior.

auditd:AUTH
AN0493 Analytic 0493 DET0174

Detects adversary exploitation of authentication mechanisms or credential validation processes. Defender perspective includes forged Kerberos tickets (e.g., MS14-068), abnormal LSASS memory access, replayed authentication attempts, and unexpected crashes of authentication services. Multi-event correlation ties exploitation attempts to abnormal process creation, service instability, and suspicious authentication events.

WinEventLog:Security WinEventLog:Sysmon
AN0494 Analytic 0494 DET0174

Detects exploitation of authentication daemons or PAM modules. Defender perspective includes failed or anomalous PAM authentications, abnormal segfaults in authentication services, and exploitation attempts followed by successful unauthorized logins. Correlation identifies memory corruption, replay attempts, and privilege escalation tied to credential services.

auditd:SYSCALL NSM:Connections
AN0496 Analytic 0496 DET0174

Detects exploitation of vulnerabilities in cloud identity providers (IdPs) such as Azure AD or Okta for credential access. Defender perspective includes anomalous token creation or renewal, authentication bypass events, and API abuse to mint unauthorized tokens. Correlation highlights exploitation attempts tied to absent or inconsistent audit logs.

azure:signinlogs m365:unified
AN0501 Analytic 0501 DET0176

Post-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations.

azure:signinlogs m365:unified saas:auth AWS:CloudTrail
AN0526 Analytic 0526 DET0185

Use of AWS STS or GCP IAM APIs to request temporary tokens or federation sessions inconsistent with normal account activity, including from unexpected principals or regions.

AWS:CloudTrail AWS:CloudTrail
AN0527 Analytic 0527 DET0185

OAuth or SAML access tokens reused across multiple sessions or clients without corresponding MFA or login activity.

azure:signinlogs m365:unified
AN0528 Analytic 0528 DET0185

Application access tokens used to call APIs (e.g., Google Workspace, Salesforce) without interactive logins, often with unusual scopes or elevated permissions.

saas:googleworkspace saas:salesforce
AN0530 Analytic 0530 DET0185

Compromised service account tokens mounted inside containers and reused for external API calls or lateral movement across services.

kubernetes:apiserver AWS:CloudTrail
AN0534 Analytic 0534 DET0186

Suspicious sign-ins to Graph API or sensitive resources using non-browser scripting agents (e.g., Python, PowerShell), often for programmatic access to mailbox or OneDrive content.

azure:signinlogs
AN0539 Analytic 0539 DET0188

Use of `esxcli storage` or `vim-cmd vmsvc/getallvms` by unusual sessions or through interactive shells unrelated to administrative maintenance tasks.

esxi:hostd esxi:auth
AN0546 Analytic 0546 DET0190

Detects PAM module modifications or removal of MFA hooks in /etc/pam.d/ configurations, correlated with successful authentications lacking MFA prompts.

auditd:SYSCALL NSM:Connections
AN0547 Analytic 0547 DET0190

Detects modifications to authorization plugins responsible for MFA enforcement and correlates with suspicious login sessions missing MFA prompts.

macos:unifiedlog macos:unifiedlog
AN0571 Analytic 0571 DET0198

Detection correlates anomalous Docker or Kubernetes API requests with access to logs, secrets, or service accounts. Observes unauthorized use of `docker logs`, `kubectl get secrets`, or direct API calls to Kubernetes API server endpoints. Identifies behavioral patterns where adversaries escalate from basic pod/container interaction to privileged API calls exposing sensitive credential material.

docker:api kubernetes:apiserver kubernetes:apiserver kubernetes:orchestrator
AN0591 Analytic 0591 DET0210

Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools.

auditd:SYSCALL linux:syslog
AN0592 Analytic 0592 DET0210

Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints.

macos:unifiedlog
AN0593 Analytic 0593 DET0210

Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships.

esxi:vpxd esxi:hostd
AN0642 Analytic 0642 DET0229

Suspicious querying of organization-wide directory data via Google Workspace Directory API or Outlook GAL sync in high volume from abnormal users, service accounts, or unknown device contexts.

gcp:audit m365:unified azure:signinlogs
AN0647 Analytic 0647 DET0233

Defenders may observe adversary attempts to collect or export full device configurations by detecting unusual SNMP queries, Smart Install (SMI) activity, or CLI/API commands that request running or startup configuration dumps. Correlated behaviors include high-volume read requests for sensitive OIDs, repeated use of 'show running-config' or equivalent commands from untrusted IPs, or unexpected TFTP/SCP/FTP transfers containing configuration files. These behaviors often appear in sequence: anomalous authentication or privilege escalation, followed by bulk configuration retrieval and outbound transfer.

networkdevice:syslog networkdevice:cli NSM:Flow snmp:access
AN0756 Analytic 0756 DET0270

Adversary modifies tenant policy through changes to federation configuration, trust settings, or identity provider additions in Microsoft 365/AzureAD via Portal, PowerShell, or Graph API. Includes setting authentication to federated or updating federated domains.

m365:unified azure:signinlogs
AN0758 Analytic 0758 DET0272

Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication.

networkconfig network:auth
AN0809 Analytic 0809 DET0291

Detects successful login to cloud identity portals (e.g., Okta, Azure AD, Google Identity) from atypical geolocations, devices, or user agents immediately followed by dashboard/portal navigation to sensitive pages such as user or app configuration.

azure:signinlogs saas:okta saas:okta
AN0810 Analytic 0810 DET0291

Detects login to admin consoles (e.g., Microsoft 365 Admin Center) from unrecognized users, devices, or geolocations followed by non-API data review or configuration read actions that suggest GUI dashboard use.

m365:signinlogs m365:unified m365:unified
AN0811 Analytic 0811 DET0291

Detects SaaS web login followed by dashboard or web GUI page views from unfamiliar locations, devices, or access patterns. Identifies use of sensitive reporting or configuration consoles accessed from high-risk accounts.

saas:zoom saas:salesforce saas:box
AN0830 Analytic 0830 DET0297

Execution of destructive CLI commands such as format flash:, format disk, or equivalent vendor-specific commands that erase filesystem structures. Detection correlates AAA logs showing privileged access with immediate format/erase commands.

networkdevice:cli networkdevice:syslog
AN0879 Analytic 0879 DET0314

Detects execution of capture commands via CLI (`monitor capture`, `debug packet`, etc.) or unauthorized CLI access followed by logging configuration changes on Cisco/Juniper/Arista gear.

networkdevice:syslog networkdevice:syslog networkdevice:syslog
AN0885 Analytic 0885 DET0316

Execution of CLI commands erasing file systems or storage (erase flash:, format disk, erase nvram:). Detect authentication events followed by destructive commands within the same privileged session.

networkdevice:cli networkdevice:syslog
AN0899 Analytic 0899 DET0319

Adversaries create user accounts via identity provider APIs or admin portals (e.g., Azure AD, Okta). These accounts may be assigned elevated privileges or used in chained authentication. Detection monitors Add User activity from suspicious IPs or automation sources, followed by role/permission escalation.

azure:audit azure:audit azure:signinlogs
AN0955 Analytic 0955 DET0338

Access tokens or SSH keys used without corresponding login shell or PAM module activity, particularly for remote execution.

auditd:SYSCALL NSM:Connections
AN0956 Analytic 0956 DET0338

Token replay or impersonation in federated logins without interactive browser session or MFA prompts.

azure:signinlogs m365:unified
AN0957 Analytic 0957 DET0338

Unusual reuse of OAuth access tokens from different geographic regions, without full login events.

saas:googleworkspace saas:googleworkspace
AN1000 Analytic 1000 DET0352

Detects unauthorized Kerberos ticket injection by correlating service ticket (TGS - 4769) requests with absent corresponding account logons (4624) and prior Ticket Granting Ticket (TGT - 4768) activity. Highlights anomalous service ticket generation chains involving unexpected users, hosts, or times, and suspicious injection of tickets via mimikatz-like tooling into LSASS memory. Behavior also includes network lateral movement using Kerberos authentication absent expected interactive logon patterns.

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1004 Analytic 1004 DET0354

Unusual or unauthorized external remote access attempts (e.g., RDP, VPN, Citrix) → repeated failed logins followed by a successful session from uncommon geolocations or outside business hours → subsequent internal lateral movement or data exfiltration activities.

WinEventLog:Security WinEventLog:Application WinEventLog:Sysmon
AN1087 Analytic 1087 DET0386

Enumeration of identity roles and users via API calls such as `Get-MsolRoleMember`, `az ad user list`, or Graph API tokens from unauthorized users or automation accounts.

Microsoft Entra ID Audit Logs azure:signinlogs m365:defender
AN1088 Analytic 1088 DET0386

Use of AWS CLI (`aws iam list-users`, `list-roles`), Azure CLI (`az ad user list`), or GCP CLI (`gcloud iam service-accounts list`) from endpoints or cloud shells where such activity is unexpected.

AWS:CloudTrail azure:activity
AN1106 Analytic 1106 DET0393

Token creation or access delegation where a user impersonates a higher-privileged service account or performs domain-wide delegation actions, such as GCP's serviceAccountTokenCreator or Workspace impersonation.

gcp:iam gcp:workspaceaudit
AN1107 Analytic 1107 DET0393

Detection of ApplicationImpersonation role assignment or delegated mailbox access to service principals or rarely used users, especially outside of normal hours or geographic norms.

m365:unified m365:signinlogs
AN1111 Analytic 1111 DET0395

Detects abuse of AuthorizationExecuteWithPrivileges API to gain elevated privileges via user credential prompts, typically through invocation of /usr/libexec/security_authtrampoline. Detection involves correlation of API usage, binary reputation, and prompt context.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1138 Analytic 1138 DET0407

Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.

auditd:USER_LOGIN linux:auth
AN1156 Analytic 1156 DET0412

Unusual web-based access or API scraping of password managers, single sign-on sessions, or credential sync services via browser automation or anomalous API tokens.

saas:googleworkspace saas:zoom
AN1157 Analytic 1157 DET0412

Unauthorized API or console calls to retrieve or reset password credentials, download key material, or modify SSO settings.

azure:signinlogs AWS:CloudTrail
AN1262 Analytic 1262 DET0460

Multiple failed authentication attempts using distinct username/password pairs from a single IP address or session within a short time window, targeting common services like RDP or SMB

WinEventLog:Security
AN1263 Analytic 1263 DET0460

Rapid login failures across different users from a single IP address, targeting SSH or PAM login with distinct username-password pairs

linux:syslog
AN1264 Analytic 1264 DET0460

Burst of failed authentications with rotating usernames against loginwindow or remote management service using reused breached credentials

macos:unifiedlog
AN1265 Analytic 1265 DET0460

Same source IP performing multiple authentication attempts using known breached username/password combinations across different identities in Azure AD, Okta, or Duo

azure:signinlogs
AN1266 Analytic 1266 DET0460

Multiple sign-in failures against cloud-based applications using username/password combinations leaked from unrelated domains

saas-app:auth
AN1267 Analytic 1267 DET0460

Router/firewall/syslog logs showing authentication failures with unique usernames and reused credentials from same source IP

networkdevice:syslog
AN1268 Analytic 1268 DET0460

Credential stuffing attempts against Kubernetes API or containerized login shells using stolen or leaked user credentials

kubernetes:apiserver
AN1269 Analytic 1269 DET0460

Use of leaked credential pairs against Outlook Web Access (OWA), Microsoft 365, or Exchange from a single client IP with multiple failures

m365:exchange
AN1270 Analytic 1270 DET0460

Burst of failed login attempts across VM instances using leaked credential pairs from single IP in public cloud environments

AWS:CloudTrail
AN1275 Analytic 1275 DET0463

High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe

WinEventLog:Security
AN1276 Analytic 1276 DET0463

Multiple authentication failures for valid or invalid users followed by success from same IP/user

auditd:USER_LOGIN
AN1277 Analytic 1277 DET0463

Password spraying or brute force attempts across user pool within short time intervals

azure:signinlogs
AN1278 Analytic 1278 DET0463

Multiple failed authentications in unified logs (e.g., loginwindow or sshd)

macos:unifiedlog
AN1279 Analytic 1279 DET0463

Excessive login attempts followed by success from SaaS apps like O365, Dropbox, etc.

m365:unified
AN1285 Analytic 1285 DET0465

Use of known default service accounts or root-level cloud accounts performing authentication or changes to IAM policy.

AWS:CloudTrail
AN1286 Analytic 1286 DET0465

Abuse of system-generated or default privileged accounts such as 'root' or 'vpxuser' logging into ESXi hosts.

esxi:auth
AN1287 Analytic 1287 DET0465

Login activity from default admin credentials (e.g., 'admin', 'cisco') on routers, firewalls, and switches.

networkdevice:syslog
AN1330 Analytic 1330 DET0484

Internal user account accesses shared links outside org followed by mass file download

m365:sharepoint azure:signinlogs
AN1336 Analytic 1336 DET0487

A high volume of authentication failures using a single password (or small set) across many different user accounts within a defined time window

WinEventLog:Security
AN1337 Analytic 1337 DET0487

Authentication failures across different accounts using a repeated or similar password via SSH or PAM stack within a short window

linux:syslog
AN1338 Analytic 1338 DET0487

Multiple failed login attempts across different users using common password patterns (e.g., 'Welcome2023')

macos:unifiedlog
AN1339 Analytic 1339 DET0487

Sign-in failures across enterprise SSO applications or SaaS platforms from same IP address using the same password against multiple user identities

azure:signinlogs
AN1340 Analytic 1340 DET0487

Authentication failure logs on routers/switches showing repeated use of default or common passwords across multiple accounts

networkdevice:syslog
AN1341 Analytic 1341 DET0487

Repeated failed authentication attempts to container APIs, control planes, or login shells across many user names using same password

kubernetes:audit
AN1342 Analytic 1342 DET0487

Failed authentication attempts across user mailboxes using identical or common passwords (e.g., OWA brute attempts)

m365:exchange
AN1343 Analytic 1343 DET0487

SaaS applications receiving authentication failures for dozens of accounts using same password or login signature

saas:auth
AN1406 Analytic 1406 DET0509

Detects use of session cookies or authentication tokens from unusual user agents or locations. Identifies token reuse without reauthentication or attempts to bypass MFA using previously stolen cookies.

saas:googleworkspace saas:okta
AN1427 Analytic 1427 DET0515

Programmatic access to user content via stolen access tokens in platforms like Slack, GitHub, Google Workspace — especially from new IPs, apps, or excessive resource access.

saas:googleworkspace saas:slack
AN1432 Analytic 1432 DET0516

Identifies CLI interpreter access (e.g., Cisco IOS, Juniper JUNOS) via `enable` mode or scripting-capable sessions used by uncommon accounts or from unknown IPs.

networkdevice:cli networkdevice:syslog
AN1476 Analytic 1476 DET0536

Detects anomalous wireless connections such as unexpected SSID associations, failed or repeated authentication attempts, and connections outside of known geofenced networks. Defenders should monitor wireless connection logs and event codes for network discovery, authentication, and association events.

WinEventLog:Microsoft-Windows-WLAN-AutoConfig WinEventLog:Security
AN1503 Analytic 1503 DET0546

Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.

azure:signinlogs saas:okta
AN1504 Analytic 1504 DET0546

Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.

AWS:CloudTrail gcp:audit
AN1505 Analytic 1505 DET0546

Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.

m365:unified gcp:audit
AN1506 Analytic 1506 DET0546

Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.

m365:signinlogs gcp:audit
AN1521 Analytic 1521 DET0551

Series of authentication failures (Event ID 4625) targeting the same or similar user accounts over time from one or more remote IPs

WinEventLog:Security
AN1522 Analytic 1522 DET0551

Repeated failed SSH login attempts followed by a possible success from the same remote host

linux:syslog
AN1523 Analytic 1523 DET0551

Series of failed logins from loginwindow or sshd with repeated usernames or password prompts

macos:unifiedlog
AN1524 Analytic 1524 DET0551

Multiple failed sign-in attempts from external sources across many users followed by success from the same IP

azure:signinlogs
AN1525 Analytic 1525 DET0551

Login attempt failures over SNMP, Telnet, or SSH interface, often reflected in logs or syslog events

networkdevice:syslog
AN1526 Analytic 1526 DET0551

Password guessing attempts against web-based apps (e.g., Dropbox, Google Workspace) reflected in API or sign-in logs

GCPAuditLogs:login.googleapis.com
AN1537 Analytic 1537 DET0558

Detects suspicious use of ESXi native CLI tools like esxcli and vim-cmd by unauthorized users or outside expected maintenance windows. Focus is on actions such as stopping VMs, reconfiguring network/firewall settings, and enabling SSH or logging.

esxi:vmkernel esxi:auth
AN1543 Analytic 1543 DET0560

Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon
AN1544 Analytic 1544 DET0560

Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns.

auditd:SYSCALL NSM:Connections
AN1546 Analytic 1546 DET0560

Detection of valid account abuse in IdP logs via geographic anomalies, impossible travel, risky sign-ins, and multiple MFA attempts or failures.

saas:okta
AN1547 Analytic 1547 DET0560

Detection of containerized service accounts or compromised kubeconfigs being used for cluster access from unexpected nodes or IPs.

kubernetes:audit
AN1551 Analytic 1551 DET0562

Windows environmental validation behavioral chain: (1) Rapid system discovery reconnaissance through WMI queries, registry enumeration, and network share discovery, (2) Environment-specific artifact collection (hostname, domain, IP addresses, installed software, hardware identifiers), (3) Cryptographic operations or conditional logic based on collected environmental values, (4) Selective payload execution contingent on environmental validation results, (5) Temporal correlation between discovery activities and subsequent execution or network communication

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:WMI WinEventLog:PowerShell
AN1552 Analytic 1552 DET0562

Linux environmental validation behavioral chain: (1) Intensive system enumeration through command execution (uname, hostname, ifconfig, lsblk, mount), (2) File system reconnaissance targeting specific paths, network configurations, and installed packages, (3) Process and user enumeration to validate target environment characteristics, (4) Conditional script execution or binary activation based on environmental criteria, (5) Network connectivity validation and external IP address resolution for geolocation verification

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL auditd:PROCTITLE linux:syslog
AN2034 Analytic 2034 DET0899

Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.

saas:okta saas:slack saas:zoom

Detection Strategies

54
DET0003 T1136.002 Detection Strategy - Domain Account Creation Across Platforms DET0054 Internal Spearphishing via Trusted Accounts DET0074 Detect Use of Stolen Web Session Cookies Across Platforms DET0078 Behavioral Detection of Malicious Cloud API Scripting DET0105 Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools DET0108 Detection Strategy for Data Encoding in C2 Channels DET0111 Detect Unsecured Credentials Shared in Chat Messages DET0120 Account Access Removal via Multi-Platform Audit Correlation DET0137 Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands DET0142 Behavioral Detection of CLI Abuse on Network Devices DET0148 Detection Strategy for Forged SAML Tokens DET0151 Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery DET0156 Detection Strategy for Resource Hijacking: SMS Pumping via SaaS Application Logs DET0160 Detection Strategy for Multi-Factor Authentication Request Generation (T1621) DET0174 Detection Strategy for Exploitation for Credential Access DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189) DET0185 Behavioral Detection Strategy for Use Alternate Authentication Material: Application Access Token (T1550.001) DET0186 Automated File and API Collection Detection Across Platforms DET0188 Local Storage Discovery via Drive Enumeration and Filesystem Probing DET0190 Detect MFA Modification or Disabling Across Platforms DET0198 Detect Abuse of Container APIs for Credential Access DET0210 Abuse of Domain Accounts DET0229 Enumeration of Global Address Lists via Email Account Discovery DET0233 Detection Strategy for Network Device Configuration Dump via Config Repositories DET0270 Detection of Domain or Tenant Policy Modifications via AD and Identity Provider DET0272 Detect Modification of Network Device Authentication via Patched System Images DET0291 Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access DET0297 Detection Strategy for Disk Structure Wipe via Boot/Partition Overwrite DET0314 Detection Strategy for Network Sniffing Across Platforms DET0316 Detection Strategy for Disk Content Wipe via Direct Access and Overwrite DET0319 Detection Strategy for T1136.003 - Cloud Account Creation across IaaS, IdP, SaaS, Office DET0338 Behavioral Detection Strategy for Use Alternate Authentication Material (T1550) DET0352 Detection Strategy for T1550.003 - Pass the Ticket (Windows) DET0354 Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers DET0386 Cloud Account Enumeration via API, CLI, and Scripting Interfaces DET0393 Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005) DET0395 macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection DET0407 Detection of Local Account Abuse for Initial Access and Persistence DET0412 Detect Access or Search for Unsecured Credentials Across Platforms DET0460 Credential Stuffing Detection via Reused Breached Credentials Across Services DET0463 Brute Force Authentication Failures with Multi-Platform Log Correlation DET0465 Detection of Default Account Abuse Across Platforms DET0484 Multi-Platform Cloud Storage Exfiltration Behavior Chain DET0487 Distributed Password Spraying via Authentication Failures Across Multiple Accounts DET0509 Detection of Web Session Cookie Theft via File, Memory, and Network Artifacts DET0515 Detection Strategy for T1528 - Steal Application Access Token DET0516 Behavioral Detection of Command and Scripting Interpreter Abuse DET0536 Detection Strategy for Wi-Fi Networks DET0546 Detection of Abused or Compromised Cloud Accounts for Access and Persistence DET0551 Password Guessing via Multi-Source Authentication Failure Correlation DET0558 Detection Strategy for ESXi Hypervisor CLI Abuse DET0560 Detection of Valid Account Abuse Across Platforms DET0562 Multi-Platform Execution Guardrails Environmental Validation Detection Strategy DET0899 Detect Social Engineering

Details

MITRE ID
DC0002
STIX ID
x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e
Analytics
109
Detection Strategies
54
Leaving Threaticon

This link opens an external site that isn't part of the platform.