AN0201
Analytic 0201
IaaS
Anomalous access to cloud web applications using session tokens without corresponding MFA/credential validation, often from unusual locations or device fingerprints.
AWS:CloudTrail
SessionToken used without preceding MFA or login event
AWS:CloudTrail
ConsoleLogin
[TimeWindow]
How far back to check for legitimate MFA or login events before token usage
[IPGeolocationDistance]
Threshold for flagging geographically impossible logins
AN0202
Analytic 0202
SaaS
Session cookie reuse on unmanaged browsers, devices, or client types deviating from user baseline (e.g., switching from Chrome to curl).
m365:unified
SessionId reused from different device/browser fingerprint
saas:okta
session.impersonation.start
[BrowserFingerprintMatch]
Tolerance for accepting small differences in user-agent headers
[SessionReuseTimeout]
Time gap threshold between valid session creation and reuse
AN0203
Analytic 0203
Office Suite
Web session tokens reused in native Office apps (e.g., Outlook, Teams) without associated token refresh or login behavior on the endpoint.
m365:unified
UserLoggedIn
[EndpointTokenSyncGap]
Allowed delta between endpoint login and cloud token reuse