AN0017
Analytic 0017
IaaS
Cloud login from atypical geolocation or user-agent string, followed by resource enumeration or infrastructure manipulation using cloud CLI/API
AWS:CloudTrail
ConsoleLogin, AssumeRole, ListResources
gcp:audit
None
[IPGeoRiskScore]
Tunable scoring system for evaluating geo-divergent or TOR-origin logins
[UserAgentFingerprint]
Flag rare CLI tools or browser-based sessions
[SessionDuration]
Threshold for how long between login and API access
[CloudResourceScope]
Limit monitoring to high-value resource groups or sensitive tenants
AN0018
Analytic 0018
Identity Provider
Federated login using SSO or OAuth grant to cloud control plane, followed by directory or permissions enumeration
Okta:SystemLog
user.authentication.sso, app.oauth.grant
[SSOApplicationScope]
Tune based on applications federated to high-priv cloud assets
[ClientIDScope]
Filter based on expected OIDC clients used for login
[LoginVelocity]
Track multiple geographic logins within short windows
AN0019
Analytic 0019
Office Suite
Login to M365 or Google Workspace from CLI tools or unexpected source IPs, followed by mailbox or document access
m365:unified
FileAccessed, MailboxAccessed
m365:unified
UserLoggedIn
[DevicePlatformMismatch]
Raise alerts on login from CLI when user typically uses web-only
[SensitiveDocumentAccessPattern]
Track access to documents labeled as internal/confidential
[AccessFrequencyThreshold]
Tune for high-volume document reads post login
AN0020
Analytic 0020
SaaS
Remote access to third-party SaaS with OAuth or API tokens post-initial compromise, followed by sensitive data access or configuration changes
saas:auth
LoginSuccess, APIKeyUse, AdminAction
[OAuthTokenAge]
Older tokens issued before password change may indicate compromise
[AppScope]
Restrict detection to high-value or regulated SaaS apps