Azure application consent

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2024-12-03
Category
Analytics Alert Reference
Order
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • AzureAD Audit Log

Detection Modules

Identity Threat Module

Detector Tags

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

An identity consented permissions to an application.

Attacker's Goals

Get access to credentials, data or an organization via applications with sufficient permissions.

Investigative actions

  • Follow further actions by the consenting user.
  • Check for new resource creations by the new user.
  • Check how the consenting user got to the application.
  • Verify the application creators.
  • Check what permissions the application requested.
  • Check for possible phishing in the organization.

Variations

First seen Azure admin consent to an application

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

Low

Description

An administrative identity consented permissions to an application.

Attacker's Goals

Get access to credentials, data or an organization via applications with sufficient permissions.

Investigative actions

  • Follow further actions by the consenting user.
  • Check for new resource creations by the new user.
  • Check how the consenting user got to the application.
  • Verify the application creators.
  • Check what permissions the application requested.
  • Check for possible phishing in the organization.