Sigma high test sigma

Azure AD Threat Intelligence

Indicates user activity that is unusual for the user or consistent with known attack patterns.

View Source

Detection Logic

{
  "selection": {
    "riskEventType": "investigationsThreatIntelligence"
  },
  "condition": "selection"
}

False Positives

  • We recommend investigating the sessions flagged by this detection in the context of other sign-ins from the user.

Field Validations

Loading…

Comments (0)

Loading comments...