AN1469
Analytic 1469
Identity Provider
Addition of credentials (keys, app passwords, x.509 certs) to existing cloud accounts, service principals, or OAuth apps via portal or API by non-standard identities or IP ranges.
azure:audit
Add service principal credentials, app password added, app role assignment
[MFABypassMechanism]
App password or legacy auth activity bypassing MFA policies.
[SourceIPAllowlist]
Expected IPs allowed to perform admin identity operations.
[ApplicationCredentialType]
Track types like `client_secret`, `certificate`, `password`, `federated`.
AN1470
Analytic 1470
IaaS
Cloud API usage to create/import SSH keys or generate new access keys (CreateAccessKey, ImportKeyPair, CreateLoginProfile) from non-console access or unusual principals.
AWS:CloudTrail
CreateAccessKey, ImportKeyPair, CreateLoginProfile, CreateKeyPair
gcp:audit
iam.serviceAccounts.keys.create, os-login.sshPublicKeys.add
[CallerIdentityContext]
Track root, federated identities, and STS tokens separately.
[NewCredentialUsageWindow]
Time between key creation and first use (default: 5 min).
[IAMRoleBaseline]
Expected services/accounts allowed to create keys.
AN1471
Analytic 1471
SaaS
Credential-related configuration changes in productivity apps, such as API key creation in Google Workspace, app tokens in Slack, or user-level OAuth credentials in M365.
gcp:audit
API Key Created, OAuth Client Registered
m365:unified
Set-Mailbox, Set-AppPassword, Add-MailboxPermission
[OAuthClientRedirectURIBaseline]
Detect suspicious redirect URI mismatches in new clients.
[TokenScopeSensitivity]
Highlight credentials granting excessive read/write org-wide.