-
Notifications
You must be signed in to change notification settings - Fork 587
Open
Labels
Integration: Azureazure related rulesazure related rulesRule: NewProposal for new ruleProposal for new ruleTeam: TRADE
Description
Description
No response
Target Ruleset
None
Target Rule Type
None
Tested ECS Version
No response
Query
No response
New fields required in ECS/data sources for this rule?
No response
Related issues or PRs
No response
References
- https://sapirxfed.com/2025/07/23/i-just-wanted-to-see-what-ssso-looks-like/
- https://echeloncyber.com/intelligence/entry/cyber-threat-alert-abusing-azureadssoacc-for-pivoting-from-on-premises-active-directory-to-azure
Redacted Example Data
No response
Metadata
Metadata
Assignees
Labels
Integration: Azureazure related rulesazure related rulesRule: NewProposal for new ruleProposal for new ruleTeam: TRADE