{"id":"352a54e1-74ba-4929-9d47-8193d67aba1e","title":"Azure Domain Federation Settings Modified","description":"Identifies when an user or application modified the federation settings on the domain.","author":"Austin Songer","status":"test","level":"medium","date":"2021-09-06","modified":"2022-06-08","tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078"],"technique_ids":["T1078"],"logsource":{"product":"azure","service":"auditlogs"},"falsepositives":["Federation Settings being modified or deleted may be performed by a system administrator.","Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.","Federation Settings modified from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule."],"references":["https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-monitor-federation-changes"],"source_path":"rules/cloud/azure/audit_logs/azure_federation_modified.yml","source_sha256":"ce64728e94d9dba47fb581a873750d73fe087c2a1917991b893cccabe1d181ae","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/azure/audit_logs/azure_federation_modified.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Azure Domain Federation Settings Modified\nid: 352a54e1-74ba-4929-9d47-8193d67aba1e\nstatus: test\ndescription: Identifies when an user or application modified the federation settings on the domain.\nreferences:\n    - https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-monitor-federation-changes\nauthor: Austin Songer\ndate: 2021-09-06\nmodified: 2022-06-08\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.initial-access\n    - attack.stealth\n    - attack.t1078\nlogsource:\n    product: azure\n    service: auditlogs\ndetection:\n    selection:\n        ActivityDisplayName: Set federation settings on domain\n    condition: selection\nfalsepositives:\n    - Federation Settings being modified or deleted may be performed by a system administrator.\n    - Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.\n    - Federation Settings modified from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.\n\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1078","id":"T1078","name":"Valid Accounts","page":"techniques/enterprise/T1078/"}],"data_path":"data/detection-rules/352a54e1-74ba-4929-9d47-8193d67aba1e.json","kind":"sigma"}
