Certificate-Based Authentication Enabled

 Original Source: [Sigma source]
Title: Certificate-Based Authentication Enabled
Status: test
Description:Detects when certificate based authentication has been enabled in an Azure Active Directory tenant.
References:
  -https://posts.specterops.io/passwordless-persistence-and-privilege-escalation-in-azure-98a01310be3f
  -https://goodworkaround.com/2022/02/15/digging-into-azure-ad-certificate-based-authentication/
Author: Harjot Shah Singh, '@cyb3rjy0t'
Date: 2024-03-26
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.defense-impairment'
  • -'attack.t1556'
Logsource:
  • product: azure
  • service: auditlogs
Detection:
  selection:
    OperationName: 'Authentication Methods Policy Update'
    TargetResources.modifiedProperties|contains: 'AuthenticationMethodsPolicy'
  condition:selection
Falsepositives:
  -Unknown
Level: medium