Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0008 — Behavioral Detection of Remote Cloud Logins via Valid Accounts
DET0008

Behavioral Detection of Remote Cloud Logins via Valid Accounts

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0017 Analytic 0017
IaaS

Cloud login from atypical geolocation or user-agent string, followed by resource enumeration or infrastructure manipulation using cloud CLI/API

AWS:CloudTrail ConsoleLogin, AssumeRole, ListResources gcp:audit None
[IPGeoRiskScore] Tunable scoring system for evaluating geo-divergent or TOR-origin logins
[UserAgentFingerprint] Flag rare CLI tools or browser-based sessions
[SessionDuration] Threshold for how long between login and API access
[CloudResourceScope] Limit monitoring to high-value resource groups or sensitive tenants
AN0018 Analytic 0018
Identity Provider

Federated login using SSO or OAuth grant to cloud control plane, followed by directory or permissions enumeration

Okta:SystemLog user.authentication.sso, app.oauth.grant
[SSOApplicationScope] Tune based on applications federated to high-priv cloud assets
[ClientIDScope] Filter based on expected OIDC clients used for login
[LoginVelocity] Track multiple geographic logins within short windows
AN0019 Analytic 0019
Office Suite

Login to M365 or Google Workspace from CLI tools or unexpected source IPs, followed by mailbox or document access

m365:unified FileAccessed, MailboxAccessed m365:unified UserLoggedIn
[DevicePlatformMismatch] Raise alerts on login from CLI when user typically uses web-only
[SensitiveDocumentAccessPattern] Track access to documents labeled as internal/confidential
[AccessFrequencyThreshold] Tune for high-volume document reads post login
AN0020 Analytic 0020
SaaS

Remote access to third-party SaaS with OAuth or API tokens post-initial compromise, followed by sensitive data access or configuration changes

saas:auth LoginSuccess, APIKeyUse, AdminAction
[OAuthTokenAge] Older tokens issued before password change may indicate compromise
[AppScope] Restrict detection to high-value or regulated SaaS apps

Detected Techniques

1

Lateral Movement (1)

Details

MITRE ID
DET0008
STIX ID
x-mitre-detection-strategy--f6e514c0-120a-4ab1-ae3d-aa2de14e4324
Analytics
4
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.