From 1ff4ed036bb470e8feb5ddafd9cd3a39ed85a297 Mon Sep 17 00:00:00 2001 From: mvelazco Date: Tue, 31 Oct 2023 18:01:06 -0400 Subject: [PATCH] Update azure_ad_multiple_denied_mfa_requests_for_user.yml --- .../cloud/azure_ad_multiple_denied_mfa_requests_for_user.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/cloud/azure_ad_multiple_denied_mfa_requests_for_user.yml b/detections/cloud/azure_ad_multiple_denied_mfa_requests_for_user.yml index 01a365c2a8..ba36801171 100644 --- a/detections/cloud/azure_ad_multiple_denied_mfa_requests_for_user.yml +++ b/detections/cloud/azure_ad_multiple_denied_mfa_requests_for_user.yml @@ -19,7 +19,7 @@ search: '`azure_monitor_aad` category=SignInLogs operationName="Sign-in activity how_to_implement: You must install the latest version of Splunk Add-on for Microsoft Cloud Services from Splunkbase (https://splunkbase.splunk.com/app/3110/#/details). You must be ingesting Azure Active Directory events into your Splunk environment through an EventHub. This analytic was written to be used with the azure:monitor:aad sourcetype leveraging the Signin log category. -known_false_positives: UPDATE_KNOWN_FALSE_POSITIVES +known_false_positives: Multiple denifed MFA requests in a short period of span may also be a sign of authentication errors. Investigate and filter as needed. references: - https://www.mandiant.com/resources/blog/russian-targeting-gov-business - https://arstechnica.com/information-technology/2022/03/lapsus-and-solar-winds-hackers-both-use-the-same-old-trick-to-bypass-mfa/