Sigma high test sigma
Azure AD Threat Intelligence
Indicates user activity that is unusual for the user or consistent with known attack patterns.
Detection Logic
{
"selection": {
"riskEventType": "investigationsThreatIntelligence"
},
"condition": "selection"
} False Positives
- ⚠ We recommend investigating the sessions flagged by this detection in the context of other sign-ins from the user.
Field Validations
Loading…
Comments (0)
Loading comments...