23 detection rules reference this event. View event page.Kusto (23)
- [Entra ID] Authentication Method Changed for Privileged Account severity high T1098
- Addition of a Temporary Access Pass to a Privileged Account severity high T1078, T1078.004
- Authentication Method Changed for Privileged Account severity high T1098
- Authentication Methods Changed for Privileged Account severity high T1098
- Authentications of Privileged Accounts Outside of Expected Controls severity medium T1078, T1078.004
- Correlate Unfamiliar sign-in properties & atypical travel alerts severity high T1078
- Detect non-admin requesting token for admin applications T1651
- Detect service account login on new device T1021, T1021.001, T1021.002, T1021.003, T1021.006
- Hunt for accounts with leaked credentials
- Local Admin Group Changes severity high T1098
- MFA Rejected by User severity medium T1078, T1078.004
- Possible Phishing with CSL and Network Sessions severity medium T1102, T1566
- Privileged Account Permissions Changed severity medium T1078, T1078.004
- Privileged Accounts - Sign in Failure Spikes severity high T1078, T1078.004
- Privileged User Logon from new ASN severity medium T1078, T1078.004
- Successful AWS Console Login from IP Address Observed Conducting Password Spray severity medium T1078, T1110
- Successful logon from IP and failure from a different IP severity medium T1078, T1110
- Suspicious AWS console logins by credential access alerts severity medium T1078
- Suspicious granting of permissions to an account severity medium T1098, T1548
- Suspicious modification of Global Administrator user properties severity medium T1078, T1078.004
- Suspicious VM Instance Creation Activity Detected severity medium T1078, T1106, T1526
- User Accounts - Sign in Failure due to CA Spikes severity medium T1078, T1078.004
- Workspace deletion activity from an infected device severity medium T1078, T1489