Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0291 — Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access
DET0291

Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0808 Analytic 0808
IaaS

Detects web console login events followed by read-only or metadata retrieval activity from GUI sources (e.g., browser session, mobile client) rather than API/CLI sources. Correlates across CloudTrail, IAM identity logs, and user-agent context.

AWS:CloudTrail ConsoleLogin AWS:CloudTrail Post-authentication metadata enumeration from GUI session
[UserAgentFilter] Allowlist/denylist of user agents to distinguish browser-based vs. CLI/API sessions
[TimeWindow] Maximum time delta between login and suspicious GUI activity
[PrivilegedSessionThreshold] Login attempts to dashboard using elevated IAM roles
AN0809 Analytic 0809
Identity Provider

Detects successful login to cloud identity portals (e.g., Okta, Azure AD, Google Identity) from atypical geolocations, devices, or user agents immediately followed by dashboard/portal navigation to sensitive pages such as user or app configuration.

azure:signinlogs Sign-in with unfamiliar location/device + portal navigation saas:okta user.session.start saas:okta WebUI access to administrator dashboard
[GeoIPAnomalyThreshold] Threshold for location anomalies per user profile
[UserAgentReputation] Unknown browser/device fingerprint list
[PrivilegedPageAccess] List of sensitive dashboard views for alerting
AN0810 Analytic 0810
Office Suite

Detects login to admin consoles (e.g., Microsoft 365 Admin Center) from unrecognized users, devices, or geolocations followed by non-API data review or configuration read actions that suggest GUI dashboard use.

m365:signinlogs UserLoginSuccess m365:unified ViewAdminReport m365:unified Read-only configuration review from GUI
[AdminRoleList] Roles allowed to access dashboard views
[DashboardNavigationSequence] Pageview paths or clickstreams indicating use of GUI admin console
[GeoLocationRisk] List of high-risk regions or unexpected geos
AN0811 Analytic 0811
SaaS

Detects SaaS web login followed by dashboard or web GUI page views from unfamiliar locations, devices, or access patterns. Identifies use of sensitive reporting or configuration consoles accessed from high-risk accounts.

saas:zoom Zoom Admin Dashboard accessed from unfamiliar IP/device saas:salesforce Login saas:box User navigated to admin interface
[SaaSDashboardViewList] List of GUI pages or endpoints considered sensitive
[IPReputationThreshold] Reputation score or allowlist of source IPs
[LoginBehaviorBaseline] Typical user/device login pairings or login frequency

Detected Techniques

1

Details

MITRE ID
DET0291
STIX ID
x-mitre-detection-strategy--e2bf0a76-b5e4-4a23-adbb-024454f5dbdc
Analytics
4
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.