Potential MFA Bypass Using Legacy Client Authentication

 Original Source: [Sigma source]
Title: Potential MFA Bypass Using Legacy Client Authentication
Status: test
Description:Detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
References:
  -https://web.archive.org/web/20230217071802/https://blooteem.com/march-2022
  -https://www.microsoft.com/en-us/security/blog/2021/10/26/protect-your-business-from-password-sprays-with-microsoft-dart-recommendations/
Author: Harjot Singh, '@cyb3rjy0t'
Date: 2023-03-20
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.credential-access'
  • -'attack.stealth'
  • -'attack.t1078.004'
  • -'attack.t1110'
Logsource:
  • product: azure
  • service: signinlogs
Detection:
  selection:
    Status: 'Success'
    userAgent|contains:
      -'BAV2ROPC'
      -'CBAinPROD'
      -'CBAinTAR'

  condition:selection
Falsepositives:
  -Known Legacy Accounts
Level: high