TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Monitoring High Risk Azure Logins

BHIS · 2024-09-12 · Read original ↗

ATT&CK techniques detected

5 predictions
T1556.006Multi-Factor Authentication
79%
"using to make these detections. the most useful attributes being ip address, operating system, asn, and country of origin. once an atrisk login has been identified, i start my investigation by querying the related user account and comparing the surrounding log ’ s login informati…"
T1078.004Cloud Accounts
73%
"in the attack chain. i hope this helps you as well. sigma rule : title : high risk azure login requiring mfa status : tested description : this detection leverages azure ad ’ s built - in service, azure ad identity protection, to detect anomalous high risk sign ins to cloud accou…"
T1078.004Cloud Accounts
58%
"monitoring high risk azure logins monitoring high risk azure logins recently in the soc, we were notified by a partner that they had a potential business email compromise, or bec. we commonly catch these by identifying suspicious email forwarding rules, utilizing anomaly detectio…"
T1621Multi-Factor Authentication Request Generation
47%
"using to make these detections. the most useful attributes being ip address, operating system, asn, and country of origin. once an atrisk login has been identified, i start my investigation by querying the related user account and comparing the surrounding log ’ s login informati…"
T1525Implant Internal Image
31%
"monitoring high risk azure logins monitoring high risk azure logins recently in the soc, we were notified by a partner that they had a potential business email compromise, or bec. we commonly catch these by identifying suspicious email forwarding rules, utilizing anomaly detectio…"

Summary

Recently in the SOC, we were notified by a partner that they had a potential business email compromise, or BEC. We commonly catch these by identifying suspicious email forwarding rules, […]

The post Monitoring High Risk Azure Logins  appeared first on Black Hills Information Security, Inc..