Detectionlowtest

Failed Authentications From Countries You Do Not Operate Out Of

Detect failed authentications from countries you do not operate out of.

Convert In Phoenix Studio

Open this Sigma rule in the converter with the YAML preloaded and ready for backend selection.

Launch
Mike DuddingtonCreated Thu Jul 2828870ae4-6a13-4616-bd1a-235a7fad7458cloud
Log Source
Azuresigninlogs
ProductAzure← raw: azure
Servicesigninlogs← raw: signinlogs
Detection Logic
Detection Logic2 selectors
detection:
    selection:
        Status: 'Success'
    selection1:
        Location|contains: '<Countries you DO operate out of e,g GB, use OR for multiple>'
    condition: not selection and not selection1
False Positives

If this was approved by System Administrator.

Rule Metadata
Rule ID
28870ae4-6a13-4616-bd1a-235a7fad7458
Status
test
Level
low
Type
Detection
Created
Thu Jul 28
Path
rules/cloud/azure/signin_logs/azure_ad_failed_auth_from_countries_you_do_not_operate_out_of.yml
Raw Tags
attack.privilege-escalationattack.persistenceattack.defense-evasionattack.initial-accessattack.credential-accessattack.t1078.004attack.t1110
View on GitHub