Use of Legacy Authentication Protocols

 Original Source: [Sigma source]
Title: Use of Legacy Authentication Protocols
Status: test
Description:Alert on when legacy authentication has been used on an account
References:
  -https://learn.microsoft.com/en-gb/entra/architecture/security-operations-privileged-accounts
Author: Yochana Henderson, '@Yochana-H'
Date: 2022-06-17
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.credential-access'
  • -'attack.stealth'
  • -'attack.t1078.004'
  • -'attack.t1110'
Logsource:
  • product: azure
  • service: signinlogs
Detection:
  selection:
    ActivityDetails: 'Sign-ins'
    ClientApp:
      -'Other client'
      -'IMAP'
      -'POP3'
      -'MAPI'
      -'SMTP'
      -'Exchange ActiveSync'
      -'Exchange Web Services'

    Username: 'UPN'
  condition:selection
Falsepositives:
  -User has been put in acception group so they can use legacy authentication
Level: high