Valid Accounts T1078
Tactics: Stealth, Persistence, Privilege Escalation, Initial Access
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Events covered
38 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 756 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (721 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (2308 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (582 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 124 rules
- Account Created And Deleted Within A Close Time Frame
- Account Disabled or Blocked for Sign in Attempts
- Account renamed to admin (or likely) account to evade defense
- Account Tampering - Suspicious Failed Logon Reasons
- Activity From Anonymous IP Address
- Admin User Remote Logon
- Application AppID Uri Configuration Changes
- Application URI Configuration Changes
- Application Using Device Code Authentication Flow
- Applications That Are Using ROPC Authentication Flow
- Attempt To Get Credentials For Identity
- Attempt To Get Federation Token
- Attempt To Get Signin Token
- Atypical Travel
- Authentications To Important Apps Using Single Factor Authentication
- AWS IAM S3Browser LoginProfile Creation
- AWS IAM S3Browser Templated S3 Bucket Policy Creation
- AWS IAM S3Browser User or AccessKey Creation
- AWS Key Pair Import Activity
- AWS Root Credentials
- AWS SAML Provider Deletion Activity
- AWS Successful Console Login Without MFA
- AWS Suspicious SAML Activity
- Azure AD Only Single Factor Authentication Required
- Azure AD Threat Intelligence
- Azure Domain Federation Settings Modified
- Azure Kubernetes Admission Controller
- Azure Login Bypassing Conditional Access Policies
- Azure Subscription Permission Elevation Via ActivityLogs
- Azure Subscription Permission Elevation Via AuditLogs
- Azure Unusual Authentication Interruption
- Azure Windows virtual machine login via serial console
- Bitbucket User Login Failure
- Bitlocker Key Retrieval
- Brutforce with denied access due to account restrictions policies
- Changes To PIM Settings
- Cisco BGP Authentication Failures
- Cisco LDP Authentication Failures
- Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
- Console Login With MFA
- Console Login Without MFA
- Device Registration or Join Without MFA
- DMSA Link Attributes Modified
- DMSA Service Account Created in Specific OUs - PowerShell
- External Remote RDP Logon from Public IP
- External Remote SMB Logon from Public IP
- Failed Authentications From Countries You Do Not Operate Out Of
- Failed Logon From Public IP
- Get Credentials For Identity
- Get Federation Token
- Get Signin Token
- Github New Secret Created
- Github Self Hosted Runner Changes Detected
- Github SSH Certificate Configuration Changed
- Google Cloud Kubernetes Admission Controller
- Google Workspace Government Attack Warning
- Guest Account Enabled Via Sysadminctl
- Guest User Invited By Non Approved Inviters
- Guest Users Invited To Tenant By Non Approved Inviters
- Huawei BGP Authentication Failures
- Impossible Travel
- Increased Failed Authentications Of Any Type
- Invalid PIM License
- Juniper BGP Missing MD5
- Kubernetes Admission Controller Modification
- Lateral movement detection (based on "special groups" feature)
- Login to Disabled Account
- Logon from a Risky IP Address
- macOS Authentication Events
- macOS SSH Connection Detection
- macOS Sudo Privilege Escalation Attempts
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure
- Measurable Increase Of Successful Authentications
- Microsoft 365 - Impossible Travel Activity
- Multifactor Authentication Denied
- Multifactor Authentication Interrupted
- Network login performed to multiple targets
- New Country
- New DMSA Service Account Created in Specific OUs
- Okta New Admin Console Behaviours
- OpenCanary - SSH Login Attempt
- OpenCanary - SSH New Connection Attempt
- OpenCanary - Telnet Login Attempt
- Password Provided In Command Line Of Net.EXE
- Password Reset By User Account
- PIM Alert Setting Changes To Disabled
- PIM Approvals And Deny Elevation
- Potential MFA Bypass Using Legacy Client Authentication
- Privileged Account Creation
- RDP reconnaissance with valid credentials performed on multiple hosts
- Refresh Token Exchange from Excessive Locations
- Refresh Token Exchange from Multiple User Agents
- Refresh Token Reuse Detection
- Roles Activated Too Frequently
- Roles Activation Doesn't Require MFA
- Roles Are Not Being Used
- Roles Assigned Outside PIM
- Root Account Enable Via Dsenableroot
- Sign-in Failure Due to Conditional Access Requirements Not Met
- Sign-ins by Unknown Devices
- Sign-ins from Non-Compliant Devices
- SQL Server - Connection attempt using a disabled account
- Stale Accounts In A Privileged Role
- Success login attempt on a Windows OpenSSH server
- Successful Authentications From Countries You Do Not Operate Out Of
- Suspicious Browser Activity
- Suspicious Computer Machine Password by PowerShell
- Suspicious Login Activity Classified By Google
- Suspicious Remote Logon with Explicit Credentials
- Suspicious SignIns From A Non Registered Device
- Temporary Access Pass Added To An Account
- Too Many Global Admins
- Unfamiliar Sign-In Properties
- Use of Legacy Authentication Protocols
- User Access Blocked by Azure Conditional Access
- User Added To Admin Group Via Dscl
- User Added To Admin Group Via DseditGroup
- User Added To Admin Group Via Sysadminctl
- User Added to an Administrator's Azure AD Role
- User Added to Local Administrator Group
- User Added To Privilege Role
- User State Changed From Guest To Member
- Users Added to Global or Device Admin Roles
- Users Authenticating To Other Azure AD Tenants
Elastic 188 rules
- Access to a Sensitive LDAP Attribute
- Account Discovery Command via SYSTEM Account
- AdminSDHolder Backdoor
- AdminSDHolder SDProp Exclusion Added
- Apple Scripting Execution with Administrator Privileges
- Attempt to Enable the Root Account
- AWS Access Token Used from Multiple Addresses
- AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN
- AWS Bedrock Foundation Model Enumeration Followed by Invocation via Long-Term Key
- AWS CloudShell Environment Created
- AWS Credentials Used from GitHub Actions and Non-CI/CD Infrastructure
- AWS EC2 Instance Console Login via Assumed Role
- AWS EC2 Instance Interaction with IAM Service
- AWS EC2 Instance Profile Associated with Running Instance
- AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role
- AWS IAM API Calls via Temporary Session Tokens
- AWS IAM Assume Role Policy Update
- AWS IAM CompromisedKeyQuarantine Policy Attached to User
- AWS IAM Login Profile Added for Root
- AWS IAM Login Profile Added to User
- AWS IAM Long-Term Access Key Correlated with Elevated Detection Alerts
- AWS IAM Long-Term Access Key First Seen from Source IP
- AWS IAM OIDC Provider Created by Rare User
- AWS IAM SAML Provider Created
- AWS IAM Sensitive Operations via Lambda Execution Role
- AWS IAM Virtual MFA Device Registration Attempt with Session Token
- AWS Management Console Root Login
- AWS Rare Source AS Organization Activity
- AWS Sign-In Console Login with Federated User
- AWS Sign-In Root Password Recovery Requested
- AWS Sign-In Token Created
- AWS STS AssumeRole with New MFA Device
- AWS STS AssumeRoot by Rare User and Member Account
- AWS STS GetSessionToken Usage
- AWS STS Role Assumption by User
- AWS STS Role Chaining
- AWS Suspicious User Agent Fingerprint
- Azure Arc Cluster Credential Access by Identity from Unusual Source
- Azure Automation Account Created
- Azure Kubernetes Services (AKS) Kubernetes Rolebindings Created
- Azure Service Principal Sign-In Followed by Arc Cluster Credential Access
- Azure Storage Account Keys Accessed by Privileged User
- CyberArk Privileged Access Security Error
- Delegated Managed Service Account Modification by an Unusual User
- dMSA Account Creation by an Unusual User
- Entra ID Actor Token User Impersonation Abuse
- Entra ID Concurrent Sign-in with Suspicious Properties
- Entra ID External Guest User Invited
- Entra ID High Risk Sign-in
- Entra ID High Risk User Sign-in Heuristic
- Entra ID Kali365 Default User-Agent Detected
- Entra ID Microsoft Authentication Broker Sign-In to Unusual Resource
- Entra ID Microsoft Authentication Broker Sign-In with Non-Standard User Agent
- Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource
- Entra ID OAuth Device Code Flow with Concurrent Sign-ins
- Entra ID OAuth Device Code Grant by Microsoft Authentication Broker
- Entra ID OAuth Device Code Grant by Unusual User
- Entra ID OAuth Device Code Phishing via AiTM
- Entra ID OAuth Flow by Microsoft Authentication Broker to Device Registration Service (DRS)
- Entra ID OAuth Phishing via First-Party Microsoft Application
- Entra ID OAuth PRT Issuance to Non-Managed Device Detected
- Entra ID OAuth ROPC Grant Login Detected
- Entra ID OAuth User Impersonation to Microsoft Graph
- Entra ID OAuth user_impersonation Scope for Unusual User and Client
- Entra ID PowerShell Sign-in
- Entra ID Privileged Identity Management (PIM) Role Modified
- Entra ID Protection - Risk Detection - Sign-in Risk
- Entra ID Protection - Risk Detection - User Risk
- Entra ID Protection Admin Confirmed Compromise
- Entra ID Protection Alerts for User Detected
- Entra ID Protection User Alert and Device Registration
- Entra ID Service Principal Federated Credential Authentication by Unusual Client
- Entra ID Service Principal with Unusual Source ASN
- Entra ID Sharepoint or OneDrive Accessed by Unusual Client
- Entra ID User Added as Service Principal Owner
- Entra ID User Reported Suspicious Activity
- Entra ID User Sign-in with Unusual Authentication Type
- Entra ID User Sign-in with Unusual Client
- Entra ID User Sign-in with Unusual Non-Managed Device
- Execution with Explicit Credentials via Scripting
- External User Added to Google Workspace Group
- First Occurrence of GitHub Repo Interaction From a New IP
- First Occurrence of IP Address For GitHub Personal Access Token (PAT)
- First Occurrence of IP Address For GitHub User
- First Occurrence of Okta User Session Started via Proxy
- First Occurrence of Personal Access Token (PAT) Use For a GitHub User
- First Occurrence of Private Repo Event from Specific GitHub Personal Access Token (PAT)
- First Occurrence of User Agent For a GitHub Personal Access Token (PAT)
- First Occurrence of User-Agent For a GitHub User
- First Time Seen Account Performing DCSync
- First Time Seen Google Workspace OAuth Login from Third-Party Application
- First-Time FortiGate Administrator Login
- FortiGate Administrator Login from Multiple IP Addresses
- FortiGate FortiCloud SSO Login from Unusual Source
- FortiGate SSL VPN Login Followed by SIEM Alert by User
- GCP IAM Custom Role Creation
- Github Activity on a Private Repository from an Unusual IP
- Google Workspace Device Registration Burst for Single User
- Google Workspace Login Flagged Suspicious
- Google Workspace Suspended User Account Renewed
- Google Workspace User Login with Unusual ASN
- Google Workspace User Sign-in from Atypical Device Type
- High Command Line Entropy Detected for Privileged Commands
- High Number of Okta User Password Reset or Unlock Attempts
- Kerberos Pre-authentication Disabled for User
- Kubeconfig File Creation or Modification
- Kubernetes Anonymous Request Authorized by Unusual User Agent
- Kubernetes Suspicious Assignment of Controller Service Account
- Kubernetes Unusual Decision by User Agent
- M365 Entra ID Risk Detection Signal
- M365 Identity Login from Atypical Region
- M365 Identity Login from Impossible Travel Location
- M365 Identity OAuth Flow by First-Party Microsoft App from Multiple IPs
- M365 Identity OAuth Phishing via First-Party Microsoft Application
- M365 Identity Unusual SSO Authentication Errors for User
- M365 Identity User Account Lockouts
- M365 or Entra ID Identity Sign-in from a Suspicious Source
- Microsoft Graph Request User Impersonation by Unusual Client
- Mounting Hidden or WebDav Remote Shares
- Multiple Okta User Auth Events with Same Device Token Hash Behind a Proxy
- New Okta Authentication Behavior Detected
- Okta Admin Console Login Failure
- Okta Alerts Following Unusual Proxy Authentication
- Okta Sign-In Events via Third-Party IdP
- Okta Successful Login After Credential Attack
- Okta User Session Impersonation
- Okta User Sessions Started from Different Geolocations
- Potential Account Takeover - Logon from New Source IP
- Potential Account Takeover - Mixed Logon Types
- Potential Admin Group Account Addition
- Potential Credential Access via DCSync
- Potential Hidden Local User Account Creation
- Potential Impersonation Attempt via Kubectl
- Potential Okta MFA Bombing via Push Notifications
- Potential Privileged Escalation via SamAccountName Spoofing
- Potential Successful SSH Brute Force Attack
- Potential Suspicious DebugFS Root Device Access
- Potentially Successful Okta MFA Bombing via Push Notifications
- Rare User Logon
- Remote Computer Account DnsHostName Update
- Spike in Group Application Assignment Change Events
- Spike in Group Lifecycle Change Events
- Spike in Group Management Events
- Spike in Group Membership Events
- Spike in Group Privilege Change Events
- Spike in Logon Events
- Spike in Privileged Command Execution by a User
- Spike in Special Logon Events
- Spike in Special Privilege Use Events
- Spike in Successful Logon Events from a Source IP
- Spike in User Account Management Events
- Spike in User Lifecycle Management Change Events
- Successful Application SSO from Rare Unknown Client Device
- Successful SSH Authentication from Unusual IP Address
- Successful SSH Authentication from Unusual SSH Public Key
- Successful SSH Authentication from Unusual User
- Suspicious Activity Reported by Okta User
- Unauthorized Access to an Okta Application
- Unauthorized Scope for Public App OAuth2 Token Grant with Client Credentials
- Unusual AWS Command for a User
- Unusual AWS S3 Object Encryption with SSE-C
- Unusual Azure Activity Logs Event for a User
- Unusual City For a GCP Event
- Unusual City For an AWS Command
- Unusual City for an Azure Activity Logs Event
- Unusual Country For a GCP Event
- Unusual Country For an AWS Command
- Unusual Country for an Azure Activity Logs Event
- Unusual GCP Event for a User
- Unusual Group Name Accessed by a User
- Unusual Host Name for Okta Privileged Operations Detected
- Unusual Host Name for Windows Privileged Operations Detected
- Unusual Hour for a User to Logon
- Unusual Interactive Shell Launched from System User
- Unusual Linux Username
- Unusual Login via System User
- Unusual Privilege Type assigned to a User
- Unusual Process Detected for Privileged Commands by a User
- Unusual Region Name for Okta Privileged Operations Detected
- Unusual Region Name for Windows Privileged Operations Detected
- Unusual Source IP for a User to Logon from
- Unusual Source IP for Okta Privileged Operations Detected
- Unusual Source IP for Windows Privileged Operations Detected
- Unusual Spike in Concurrent Active Sessions by a User
- Unusual Windows Remote User
- Unusual Windows User Privilege Elevation Activity
- Unusual Windows Username
- User Added to the Admin Group
Splunk 78 rules
- Account set to active via Net.exe (EDR)
- Account set to active via Net.exe (Sysmon)
- Account set to active via Net.exe (Windows Event Log)
- ASL AWS Create Policy Version to allow all resources
- ASL AWS SAML Update identity provider
- AWS Bedrock Invoke Model Access Denied
- AWS Create Policy Version to allow all resources
- AWS SAML Update identity provider
- AWS SetDefaultPolicyVersion
- AWS Successful Single-Factor Authentication
- Azure AD Authentication Failed During MFA Challenge
- Azure AD Multiple AppIDs and UserAgents Authentication Spike
- Azure AD Multiple Failed MFA Requests For User
- Azure AD Service Principal Authentication
- Azure AD Successful PowerShell Authentication
- Azure AD Successful Single-Factor Authentication
- Azure Runbook Webhook Created
- Cisco ASA - New Local User Account Created
- Cisco ASA - User Privilege Level Change
- Cisco IOS Suspicious Privileged Account Creation
- Cisco IOS XE WebUI Login From IOSd Local Port
- Cisco IOS XE WebUI Programmatic Configuration
- Cisco Privileged Account Creation with HTTP Command Execution
- Cisco Privileged Account Creation with Suspicious SSH Activity
- Cisco Secure Firewall - High Priority Intrusion Classification
- Cloud API Calls From Previously Unseen User Roles
- Cloud Compute Instance Created By Previously Unseen User
- Cloud Instance Modified By Previously Unseen User
- Cloud Provisioning Activity From Previously Unseen City
- Cloud Provisioning Activity From Previously Unseen Country
- Cloud Provisioning Activity From Previously Unseen IP Address
- Cloud Provisioning Activity From Previously Unseen Region
- Detect Excessive Account Lockouts From Endpoint
- Detect Excessive User Account Lockouts
- ESXi Account Modified
- ESXi External Root Login Activity
- ESXi Shared or Stolen Root Account
- ESXi User Granted Admin Role
- GCP Authentication Failed During MFA Challenge
- GCP Detect gcploit framework
- GCP Multiple Failed MFA Requests For User
- GCP Successful Single-Factor Authentication
- Geographic Improbable Location
- M365 Copilot Application Usage Pattern Anomalies
- M365 Copilot Session Origin Anomalies
- Multiple Host logons (Windows Event Log)
- O365 Multiple AppIDs and UserAgents Authentication Spike
- O365 Security And Compliance Alert Triggered
- Okta Authentication Failed During MFA Challenge
- Okta New API Token Created
- Okta Non-Standard VPN Usage
- Okta Phishing Detection with FastPass Origin Check
- Okta Risk Threshold Exceeded
- Okta Successful Single Factor Authentication
- Okta Suspicious Activity Reported
- Okta ThreatInsight Threat Detected
- PingID Multiple Failed MFA Requests For User
- Potential password in username
- Rubeus Password Change (Windows Event Log)
- Short Lived Windows Accounts
- Suspicious Computer Account Name Change
- Suspicious Kerberos Service Ticket Request
- Suspicious Ticket Granting Ticket Request
- Unusual Number of Computer Service Tickets Requested
- Unusual Number of Remote Endpoint Authentication Events
- Windows Azure PowerShell Module Installation Via PowerShell Script
- Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
- Windows Entra User Management Via Azure CLI
- Windows Group Policy Object Created
- Windows Guest Account Enabled Via Net.EXE
- Windows Large Number of Computer Service Tickets Requested
- Windows Multiple Account Passwords Changed
- Windows Multiple Accounts Deleted
- Windows Multiple Accounts Disabled
- Windows PowerView AD Access Control List Enumeration
- WMIC Explicit Credentials (Sysmon)
- WMIC Explicit Credentials (Windows Event Log)
- Zoom High Video Latency
Kusto 239 rules
- Account added and removed from privileged groups
- Account Created and Deleted in Short Timeframe
- Account created or deleted by non-approved user
- Account Elevated to New Role
- Acronis - Login from Abnormal IP - Low Occurrence
- Addition of a Temporary Access Pass to a Privileged Account
- Admin promotion after Role Management Application Permission Grant
- AdminSDHolder Modifications
- Anomalous login followed by Teams action
- Anomalous sign-in location by user account and authenticating application
- Anomalous Single Factor Signin
- Anomaly Sign In Event from an IP
- ApexOne - Device access permissions was changed
- Application ID URI Changed
- Application Redirect URL Update
- Attempt to bypass conditional access rule in Microsoft Entra ID
- Attempts to sign in to disabled accounts
- Authentication Attempt from New Country
- Authentications of Privileged Accounts Outside of Expected Controls
- AWS Security Hub - Detect IAM Policies allowing full administrative privileges
- AWSCloudTrail - Changes to Amazon VPC settings
- AWSCloudTrail - Login to AWS Management Console without MFA
- AWSCloudTrail - NRT Login to AWS Management Console without MFA
- AWSCloudTrail - SAML update identity provider
- Azure Machine Learning Write Operations
- Azure RBAC (Elevate Access)
- Bitglass - Impossible travel distance
- Bitglass - Login from new device
- Bitglass - New admin user
- Bitglass - New risky user
- Bitglass - User Agent string has changed for user
- Bitglass - User login from new geo location
- Box - Inactive user login
- Box - New external user
- Box - User logged in as admin
- Box - User role changed to owner
- BTP - Build Work Zone unauthorized access and role tampering
- BTP - User added to Cloud Identity Service privileged Administrators list
- BTP - User added to sensitive privileged role collection
- Bulk Changes to Privileged Account Permissions
- Changes to Application Logout URL
- Changes to Application Ownership
- Changes to PIM Settings
- Cisco - firewall block but success logon to Microsoft Entra ID
- Cisco Duo - Admin password reset
- Cisco Duo - Admin user created
- Cisco Duo - Authentication device new location
- Cisco Duo - Multiple admin 2FA failures
- Cisco Duo - Multiple user login failures
- Cisco Duo - New access device
- Cisco Duo - Unexpected authentication factor
- Conditional Access - A Conditional Access user/group/role exclusion has changed
- Conditional Access Policy Modified by New User
- Copilot - Jailbreak Attempt Detected
- Correlate Unfamiliar sign-in properties & atypical travel alerts
- Cross-Cloud Suspicious Compute resource creation in GCP
- Cross-Cloud Suspicious user activity observed in GCP Envourment
- Cross-tenant Access Settings Organization Added
- Cross-tenant Access Settings Organization Deleted
- Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed
- Cross-tenant Access Settings Organization Inbound Direct Settings Changed
- Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed
- Cross-tenant Access Settings Organization Outbound Direct Settings Changed
- Dataverse - Hierarchy security manipulation
- Dataverse - Login by a sensitive privileged user
- Dataverse - Login from IP in the block list
- Dataverse - Login from IP not in the allow list
- Dataverse - New Dataverse application user activity type
- Dataverse - New non-interactive identity granted access
- Dataverse - New sign-in from an unauthorized domain
- Dataverse - New user agent type that was not used before
- Dataverse - Organization settings modified
- Dataverse - TI map IP to DataverseActivity
- Detect changes to Connect Sync Application
- Detect credential add to Connect Sync Application
- Detect device code login with user risk
- Detect PIM Alert Disabling activity
- Detecting Impossible travel with mailbox permission tampering & Privilege Escalation attempt
- EatonForeseer - Unauthorized Logins
- Elevation of Privilege attempt detected
- Email access via active sync
- End-user consent stopped due to risk-based consent
- External guest invitation followed by Microsoft Entra ID PowerShell signin
- F&O - Bank account change following network alias reassignment
- F&O - Non-interactive account mapped to self or sensitive privileged user
- F&O - Unusual sign-in activity using single factor authentication
- Failed AWS Console logons but success logon to AzureAD
- Failed AzureAD logons but success logon to AWS Console
- Failed AzureAD logons but success logon to host
- Failed host logons but success logon to AzureAD
- Failed sign-ins into LastPass due to MFA
- GCP Audit Logs - Data Access Logging Exemption Added for Principal
- GCP Audit Logs - Storage Bucket Made Public
- GCP IAM - High privileged role added to service account
- GitHub - A payment method was removed
- GitHub - Oauth application - a client secret was removed
- GitHub - pull request was created
- GitHub - pull request was merged
- GitHub - Repository was created
- GitHub - Repository was destroyed
- GitHub - User visibility Was changed
- GitHub - User was added to the organization
- GitHub - User was blocked
- GitHub - User was invited to the repository
- GitHub Activites from a New Country
- GitLab - TI - Connection from Malicious IP
- GitLab - User Impersonation
- Group created then added to built in domain local or global group
- GSA - Detect Connections Outside Operational Hours
- Guest accounts added in Entra ID Groups other than the ones specified
- Guest Users Invited to Tenant by New Inviters
- High risk Office operation conducted by IP Address that recently attempted to log into a disabled account
- High-Risk Cross-Cloud User Impersonation
- Hunt for critical credentials on devices with non-critical accounts
- Hunt for privilege escalation paths with high ACLs
- Illusive Incidents Analytic Rule
- IP with multiple failed Microsoft Entra ID logins successfully logs in to Palo Alto VPN
- Jira - Global permission added
- Jira - New site admin user
- Jira - New site admin user
- Jira - New user created
- Jira - User's password changed multiple times
- M365D Alerts Correlation to non-Microsoft Network device network activity involved in successful sign-in Activity
- Malicious BEC Inbox Rule
- Malicious Inbox Rule
- MFA Rejected by User
- Microsoft Entra ID PowerShell accessing non-Entra ID resources
- Microsoft Entra ID Role Management Permission Grant
- Multiple Password Reset by user
- Netskope - Impossible Travel Detection (Two Countries in Less Than 1 Hour)
- New country signIn with correct password
- New Device/Location sign-in along with critical operation
- New PA, PCA, or PCAS added to Azure DevOps
- New User Assigned to Privileged Role
- New user created and added to the built-in administrators group
- Non-admin guest
- NRT Malicious Inbox Rule
- NRT PIM Elevation Request Rejected
- NRT Privileged Role Assigned Outside PIM
- NRT User added to Microsoft Entra ID Privileged Groups
- OracleDBAudit - Connection to database from external IP
- OracleDBAudit - Connection to database from unknown IP
- OracleDBAudit - New user account
- OracleDBAudit - User activity after long inactivity time
- OracleDBAudit - User connected to database from new IP
- Palo Alto Prisma Cloud - Access keys are not rotated for 90 days
- Palo Alto Prisma Cloud - Anomalous access key usage
- Palo Alto Prisma Cloud - IAM Group with Administrator Access Permissions
- Palo Alto Prisma Cloud - Inactive user
- Pathlock TDnR - Emergency User (AdminTrack) Activity
- Pathlock TDnR - Multiple Login Sessions Detected
- Pathlock TDnR - SAP Cloud Account Administration Events
- Pathlock TDnR - SAP HANA Database Audit Trail
- Pathlock TDnR - User Access Management Password Resets
- PIM Elevation Request Rejected
- Ping Federate - Abnormal password resets for user
- Ping Federate - Authentication from new IP.
- Ping Federate - Forbidden country
- Ping Federate - New user SSO success login
- Ping Federate - Password reset request from unexpected source IP address..
- Ping Federate - Unexpected authentication URL.
- Ping Federate - Unexpected country for user
- Ping Federate - Unusual mail domain.
- Possible AiTM Phishing Attempt Against Microsoft Entra ID
- Potential Ransomware activity related to Cobalt Strike
- Power Apps - App activity from unauthorized geo
- Power Platform - Account added to privileged Microsoft Entra roles
- Power Platform - Possibly compromised user accesses Power Platform services
- Privileged Account Permissions Changed
- Privileged Accounts - Sign in Failure Spikes
- Privileged Role Assigned Outside PIM
- Privileged User Logon from new ASN
- ProofpointPOD - Binary file in attachment
- ProofpointPOD - Email sender in TI list
- ProofpointPOD - Email sender IP in TI list
- ProofpointPOD - Possible data exfiltration to private email
- RecordedFuture Threat Hunting Url All Actors
- Red Sift - Login from previously unseen IP address
- Semperis DSP Failed Logons
- Sentinel One - Admin login from new location
- Sentinel One - New admin created
- Service Principal Assigned App Role With Sensitive Access
- Service Principal Assigned Privileged Role
- Service Principal Authentication Attempt from New Country
- Service principal not using client credentials
- Sign-ins from IPs that attempt sign-ins to disabled accounts
- Sign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization)
- SlackAudit - User email linked to account changed.
- SlackAudit - User login after deactivated.
- SlackAudit - User role changed to admin or owner
- Snowflake - Multiple login failures by user
- Snowflake - Multiple login failures from single IP
- Snowflake - User granted admin privileges
- StealthTalk - After hours work
- StealthTalk - Login outside work zone
- StealthTalk - Multi new devices registration
- Successful AWS Console Login from IP Address Observed Conducting Password Spray
- Successful logins to SOC Prime platform from bad IP addresses
- Successful logon from IP and failure from a different IP
- Suspicious AWS console logins by credential access alerts
- Suspicious linking of existing user to external User
- Suspicious Login from deleted guest account
- Suspicious modification of Global Administrator user properties
- Suspicious Service Principal creation activity
- Suspicious Sign In by Entra ID Connect Sync Account
- Suspicious Sign In Followed by MFA Modification
- Suspicious VM Instance Creation Activity Detected
- Threat Essentials - NRT User added to Microsoft Entra ID Privileged Groups
- Threat Essentials - User Assigned Privileged Role
- URL Added to Application from Unknown Domain
- User account added to built in domain local or global group
- User account created and deleted within 10 mins
- User account enabled and disabled within 10 mins
- User Accounts - Sign in Failure due to CA Spikes
- User Added to Admin Role
- User added to Microsoft Entra ID Privileged Groups
- User Assigned New Privileged Role
- User joining Zoom meeting from suspicious timezone
- User Login from Different Countries within 3 hours
- User login from different countries within 3 hours (Uses Authentication Normalization)
- User Sign in from different countries
- UserAccountDisabled
- Valimail Enforce - High-Value User Management Event
- Valimail Enforce - Unusual Rate of Configuration Changes or User Additions
- vCenter - Root impersonation
- VMware ESXi - Multiple new VMs started
- VMware ESXi - New VM started
- VMware ESXi - Root impersonation
- VMware ESXi - Root login
- VMware ESXi - Root password changed
- VMware ESXi - Shared or stolen root account
- VMware vCenter - Root login
- Workspace deletion activity from an infected device
- Zscaler - Connections by dormant user
- Zscaler - Shared ZPA session
- Zscaler - Unexpected event count of rejects by policy
- Zscaler - Unexpected ZPA session duration
- Zscaler - ZPA connections by new user
- Zscaler - ZPA connections from new IP
YARA-L 29 rules
- AWS API Call Outside Of Organization
- AWS Console Login Without MFA
- AWS IAM Administrator Access Policy Attached
- AWS SAML Identity Provider Changes
- AWS Successful Login After Multiple Failed Attempts
- AWS User Creates Permanent Access Key
- Entra ID Admin Login Activity to Uncommon MS Cloud Apps
- Entra ID Login Activity to Uncommon MS Cloud Apps
- GCP Workload Identity Pool Disabled Or Deleted
- Google Workspace External User Added To Group
- Google Workspace SAML IDP Configuration Change
- Google Workspace User Unsuspended
- Logins From Terminated Employees
- O365 Admin Login Activity To Uncommon Microsoft Cloud Apps
- O365 Login Activity To Azure AD PowerShell App
- O365 Login Activity To Uncommon Microsoft Cloud Apps
- Okta Multiple User's Logins With Invalid Credentials From The Same IP
- Okta New API Token Created
- Okta Successful High Risk User Logins
- Okta User Account Lockout
- Okta User Login Out Of Hours
- Okta User Logins From Multiple Cities
- Okta User Suspicious Activity Reported
- OneLogin Multiple Users Login Failures From The Same IP
- OneLogin Super User Privileges Assigned
- OneLogin User Logins From Multiple Countries
- sap break glass account login
- sap impossible travel
- sap multi terminal logon
Panther 98 rules
- A Login from Outside the Corporate Office
- Admin Role Assigned
- AppOmni Alert Passthrough
- AWS Backdoor Administrative IAM Role Created
- AWS CloudTrail Password Spraying
- AWS Compromised IAM Key Quarantine
- AWS GuardDuty Critical Severity Finding
- AWS IAM Group Users
- AWS IAM Policy Administrative Privileges
- AWS IAM Policy Assigned to User
- AWS IAM Policy Blocklist
- AWS IAM Policy Does Not Grant Any Administrative Access
- AWS IAM Policy Does Not Grant Network Admin Access
- AWS IAM Resource Does Not Have Inline Policy
- AWS IAM Role Restricts Usage
- AWS IAM User Not In Conflicting Groups
- AWS IMDS Credential Usage Outside Expected Services
- AWS Potential Backdoor Lambda Function Through Resource-Based Policy
- AWS Root Account Hardware MFA
- AWS Root Account MFA
- AWS.Administrative.IAM.User.Created
- Azure Automation Account Created
- Azure Automation Runbook Created or Modified
- Azure Device Code Authentication with Broker Client
- Azure High-Risk Sign-In
- Azure Invite External Users
- Azure Kubernetes RoleBinding or ClusterRoleBinding Created
- Azure Many Failed SignIns
- Azure MFA Disabled
- Azure Microsoft Graph Single Session from Multiple IP Addresses
- Azure Policy DeployIfNotExists Action Triggered
- Azure Privileged or Elevated Role Assignment
- Azure Protection Multiple Alerts for User
- Azure RiskLevel Passthrough
- Azure ROPC Login Attempt Without MFA
- Box New Login
- Box Shield Suspicious Alert Triggered
- Box Untrusted Device Login
- CloudTrail Password Spraying
- Databricks Attempted Logon From Denied IP
- Databricks Delta Sharing IP Access Failures
- Databricks Employee Logon
- Databricks Non-SSO Login Detected
- Databricks Potential Privilege Escalation
- Databricks Repeated Failed Login Attempts
- GAIA GCPW Credential Theft Attack Chain
- GCP IAM Role Has Changed
- GCP User Added to Privileged Group
- GitHub User Access Key Created
- Google Workspace Login Type Anomaly
- Google Workspace OAuth Application Authorized with Privileged Scopes
- Google Workspace OAuth Token Requests from New IP
- Google Workspace Rapid Multi-IP Authentication
- GSuite Login Type
- IAM Administrator Role Policy Attached
- IAM Inline Policy Network Admin
- IAM Role Added to RDS Instance or Cluster
- IAM Role Created
- IAM Role Policy Updated to Allow Internet Access
- IAM User Created
- IAM User Policy Attached with Administrator Access
- Impossible Travel for Login Action
- Kubernetes ClusterRoleBinding to Privileged Role
- Kubernetes Role With Node Proxy Permissions Created
- Kubernetes Role With Pod Exec Permissions Created
- Kubernetes Role With Wildcard Permissions Created
- Kubernetes Service Account Token Theft from Pod
- Kubernetes System Role Modified or Deleted
- Lambda Code Updated by User
- Lambda Configuration Updated with Layers by User
- Logins Without MFA
- Logins Without SAML
- Okta AD Agent Authentication Anomaly - Z-Score Detection
- Okta Admin Role Assigned
- Okta AiTM Phishing Attempt Blocked by FastPass
- Okta Login Without Push
- Okta New Behaviors Acessing Admin Console
- Okta Org2Org application created of modified
- Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral
- Okta SWA Off-Hours Credential Access - Behavioral
- OneLogin High Risk Failed Login FOLLOWED BY Successful Login
- OpenAI Admin Role Assignment
- OpenAI Anomalous API Key Activity
- Potential Compromised Okta Credentials
- Root Account Activity
- Root Console Login
- Salesforce API Anomaly Detection (RET Passthrough)
- Sign In from Rogue State
- Slack Primary Owner Transferred
- Snowflake Account Admin Granted
- Snowflake Account Admin Granted
- Snowflake Grant to Public Role
- Suspicious Snowflake Sessions - Unusual Application
- User Logged in wihout MFA
- Wiz Rotate Service Account Secret
- Wiz Service Account Change
- Zendesk Account Owner Changed
- Zendesk Mobile App Access Modified