Title:
New Federated Domain Added
Status:
test
Description:Detects the addition of a new Federated Domain.
References:
-https://research.splunk.com/cloud/e155876a-6048-11eb-ae93-0242ac130002/
-https://o365blog.com/post/aadbackdoor/
Author: Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule)
Date: 2023-09-18
modified:None
Tags:
- -'attack.privilege-escalation'
- -'attack.defense-impairment'
- -'attack.t1484.002'
Logsource:
- service: audit
- product: m365
Detection:
selection_domain:
Operation|contains:
'domain'
selection_operation:
Operation|contains:
-'add'
-'new'
condition:
all of selection_*
Falsepositives:
-The creation of a new Federated domain is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a similar or different cloud provider.
Level:
medium