Files
splunk-security_content/detections/cloud/o365_disable_mfa.yml
2024-06-26 14:41:53 +00:00

66 lines
2.4 KiB
YAML

name: O365 Disable MFA
id: c783dd98-c703-4252-9e8a-f19d9f5c949e
version: 3
date: '2024-05-11'
author: Rod Soto, Splunk
status: production
type: TTP
description: The following analytic identifies instances where Multi-Factor Authentication
(MFA) is disabled for a user within the Office 365 environment. It leverages O365
audit logs, specifically focusing on events related to MFA settings. Disabling MFA
removes a critical security layer, making accounts more vulnerable to unauthorized
access. If confirmed malicious, this activity could indicate an attacker attempting
to maintain persistence or an insider threat, significantly increasing the risk
of unauthorized access. Immediate investigation is required to validate the reason
for disabling MFA, potentially re-enable it, and assess any other suspicious activities
related to the affected account.
data_source:
- O365 Disable Strong Authentication.
search: '`o365_management_activity` Operation="Disable Strong Authentication." | stats
count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation
UserId ResultStatus object | rename UserType AS user_type, Operation AS action,
UserId AS src_user, object AS user, ResultStatus AS result | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_disable_mfa_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: Unless it is a special case, it is uncommon to disable MFA
or Strong Authentication
references:
- https://attack.mitre.org/techniques/T1556/
tags:
analytic_story:
- Office 365 Persistence Mechanisms
asset_type: O365 Tenant
confidence: 80
impact: 80
message: User $src_user$ has executed an operation $action$ for user $user$
mitre_attack_id:
- T1556
observable:
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Operation
- UserType
- user
- status
- signature
- dest
- ResultStatus
risk_score: 64
security_domain: threat
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_disable_mfa/o365_disable_mfa.json
sourcetype: o365:management:activity
source: o365