Trusted Relationship T1199
Tactic: Initial Access
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Authoring guide
These 18 rules share fields, values, and exclusions.
Fields filtered most (45 distinct)
These fields appear most often in rule filters.
Top indicator values (102 distinct)
These values appear most often in rule predicates.
Exclusions (24 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 1 rule
Elastic 5 rules
- Entra ID Illicit Consent Grant via Registered Application
- Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource
- Entra ID OAuth Phishing via First-Party Microsoft Application
- New GitHub App Installed
- Okta Sign-In Events via Third-Party IdP
Kusto 6 rules
- Anomalous login followed by Teams action
- Azure Portal sign in from another Azure Tenant
- Dataverse - TI map IP to DataverseActivity
- External Upstream Source Added to Azure DevOps Feed
- Netskope - New Risky App Access vs 7-Day Baseline
- Netskope - Unsanctioned/Risky Cloud App Access (Shadow IT)