Short-lived Azure AD user account

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2024-12-03
Category
Analytics Alert Reference
Order
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

  • Requires:
    • AzureAD Audit Log

Detection Modules

Identity Threat Module

Detector Tags

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Informational

Description

An Azure AD user was created and deleted within a short period of time.

Attacker's Goals

Evasion using a valid account.

Investigative actions

  • Check the user who created the account and verify the activity.
  • Confirm that the account creation was not accidental.

Variations

Abnormal Short-lived Azure AD user account

Synopsis

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Valid Accounts (T1078)

Severity

Low

Description

An Azure AD user was created and deleted within a short period of time. by an identity does not regularly create and delete accounts.

Attacker's Goals

Evasion using a valid account.

Investigative actions

  • Check the user who created the account and verify the activity.
  • Confirm that the account creation was not accidental.