AN1503
Analytic 1503
Identity Provider
Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.
azure:signinlogs
Sign-in activity
saas:okta
user.authentication.sso
[AnomalousLocationThreshold]
Defines geographic separation (e.g., impossible travel) considered suspicious.
[ProtocolType]
Filter based on legacy or deprecated authentication mechanisms.
AN1504
Analytic 1504
IaaS
Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.
AWS:CloudTrail
ConsoleLogin, AssumeRole, ListAccessKeys, CreateUser
gcp:audit
admin.googleapis.com
[ServiceInteractionBaseline]
Custom list of expected service interactions per user or role.
[RoleSwitchRateThreshold]
Frequency of assume-role operations that triggers an alert.
AN1505
Analytic 1505
SaaS
Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.
m365:unified
FileAccessed, SharingSet
gcp:audit
drive.activity
[FileDownloadThreshold]
Defines excessive access based on number or size of downloads.
[SharingPolicyViolationThreshold]
Defines external sharing behaviors that violate policy.
AN1506
Analytic 1506
Office Suite
Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.
m365:signinlogs
UserLogin
gcp:audit
login.event
[BusinessHours]
Used to identify logins outside of expected work times.
[OfficeProductivityToolBaseline]
Defines expected application usage per department or role.