AN0808
Analytic 0808
IaaS
Detects web console login events followed by read-only or metadata retrieval activity from GUI sources (e.g., browser session, mobile client) rather than API/CLI sources. Correlates across CloudTrail, IAM identity logs, and user-agent context.
AWS:CloudTrail
ConsoleLogin
AWS:CloudTrail
Post-authentication metadata enumeration from GUI session
[UserAgentFilter]
Allowlist/denylist of user agents to distinguish browser-based vs. CLI/API sessions
[TimeWindow]
Maximum time delta between login and suspicious GUI activity
[PrivilegedSessionThreshold]
Login attempts to dashboard using elevated IAM roles
AN0809
Analytic 0809
Identity Provider
Detects successful login to cloud identity portals (e.g., Okta, Azure AD, Google Identity) from atypical geolocations, devices, or user agents immediately followed by dashboard/portal navigation to sensitive pages such as user or app configuration.
azure:signinlogs
Sign-in with unfamiliar location/device + portal navigation
saas:okta
user.session.start
saas:okta
WebUI access to administrator dashboard
[GeoIPAnomalyThreshold]
Threshold for location anomalies per user profile
[UserAgentReputation]
Unknown browser/device fingerprint list
[PrivilegedPageAccess]
List of sensitive dashboard views for alerting
AN0810
Analytic 0810
Office Suite
Detects login to admin consoles (e.g., Microsoft 365 Admin Center) from unrecognized users, devices, or geolocations followed by non-API data review or configuration read actions that suggest GUI dashboard use.
m365:signinlogs
UserLoginSuccess
m365:unified
ViewAdminReport
m365:unified
Read-only configuration review from GUI
[AdminRoleList]
Roles allowed to access dashboard views
[DashboardNavigationSequence]
Pageview paths or clickstreams indicating use of GUI admin console
[GeoLocationRisk]
List of high-risk regions or unexpected geos
AN0811
Analytic 0811
SaaS
Detects SaaS web login followed by dashboard or web GUI page views from unfamiliar locations, devices, or access patterns. Identifies use of sensitive reporting or configuration consoles accessed from high-risk accounts.
saas:zoom
Zoom Admin Dashboard accessed from unfamiliar IP/device
saas:salesforce
Login
saas:box
User navigated to admin interface
[SaaSDashboardViewList]
List of GUI pages or endpoints considered sensitive
[IPReputationThreshold]
Reputation score or allowlist of source IPs
[LoginBehaviorBaseline]
Typical user/device login pairings or login frequency