AN0683
Analytic 0683
Windows
Monitor call log records from corporate devices for unusual or unauthorized numbers, especially repeated calls to/from known malicious phone numbers. Correlate with subsequent system events (e.g., browser navigation, remote management tool execution).
ApplicationLog:CallRecords
Outbound or inbound calls to high-risk or blocklisted numbers
[PhoneNumberBlocklist]
List of known malicious or suspicious phone numbers; must be tuned per environment
[TimeWindow]
Threshold for correlating call events with subsequent suspicious system activity
AN0684
Analytic 0684
Linux
Audit VoIP/SIP logs for suspicious outbound calls or call setup messages to unusual endpoints. Correlate with user activity such as browser execution or package installation following the call.
networkdevice:syslog
SIP REGISTER, INVITE, or unusual call destination metadata
[CallDestinationPatterns]
Regular expressions or rules for spotting abnormal call destinations
[UserContext]
Expected users who initiate VoIP traffic vs. anomalous accounts
AN0685
Analytic 0685
macOS
Monitor Facetime, iMessage, or SIP client logs for anomalous voice call attempts. Link to subsequent user execution events (downloads, RMM installs) triggered post-call.
macos:unifiedlog
Outgoing or incoming calls with non-standard caller IDs or unusual metadata
[CallerIDPatterns]
Patterns of spoofed caller IDs that must be tuned based on region and telecom provider
[PayloadCorrelation]
Define what follow-on events (browser downloads, execution) to correlate with call logs
AN0686
Analytic 0686
Identity Provider
Correlate MFA push fatigue or unusual consent grant attempts with call activity where adversaries may have socially engineered the user over voice.
m365:unified
Unusual MFA requests or OAuth consent events temporally aligned with user-reported vishing call
[MFARequestThreshold]
Number of MFA push requests within a timeframe aligned to a suspicious call
[ConsentGrantPatterns]
Unusual OAuth consent URLs or delegated scopes