Analytics Story: Compromised User Account
Description
Monitor for activities and techniques associated with Compromised User Account attacks.
Why it matters
Compromised User Account occurs when cybercriminals gain unauthorized access to accounts by using different techniques like brute force, social engineering, phishing & spear phishing, credential stuffing, etc. By posing as the real user, cyber-criminals can change account details, send out phishing emails, steal financial information or sensitive data, or use any stolen information to access further accounts within the organization. This analytic story groups detections that can help security operations teams identify the potential signs of Compromised User Accounts.
Detections
Data Sources
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| PingID | Other | XmlWinEventLog |
XmlWinEventLog:Security |
| Azure Active Directory NonInteractiveUserSignInLogs | azure:monitor:aad |
Azure AD |
|
| Azure Active Directory MicrosoftGraphActivityLogs | azure:monitor:aad |
Azure AD |
|
| AWS CloudTrail ConsoleLogin | aws:cloudtrail |
aws_cloudtrail |
|
| Azure Active Directory | azure:monitor:aad |
Azure AD |
|
| AWS CloudTrail | aws:cloudtrail |
aws_cloudtrail |
|
| Azure Active Directory Sign-in activity | azure:monitor:aad |
Azure AD |
|
| Windows Event Log Security 4625 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| Office 365 Universal Audit Log | Other | o365:management:activity |
o365 |
| AWS CloudTrail DescribeEventAggregates | aws:cloudtrail |
aws_cloudtrail |
|
| Windows Event Log Security 4624 | XmlWinEventLog |
XmlWinEventLog:Security |
|
| ASL AWS CloudTrail | aws:asl |
aws_asl |
|
| Azure Active Directory User registered security info | azure:monitor:aad |
Azure AD |
|
| AWS CloudTrail GetAccountPasswordPolicy | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteAccountPasswordPolicy | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail UpdateAccountPasswordPolicy | aws:cloudtrail |
aws_cloudtrail |
|
| Sysmon EventID 3 | XmlWinEventLog |
XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
|
| Cisco Secure Access Firewall | Other | cisco:cloud_security:firewall |
cisco_secure_access:firewall |
References
Source: GitHub | Version: 2