{"id":"42127bdd-9133-474f-a6f1-97b6c08a4339","title":"New Federated Domain Added - Exchange","description":"Detects the addition of a new Federated Domain.","author":"Splunk Threat Research Team (original rule), '@ionsor (rule)'","status":"test","level":"medium","date":"2022-02-08","modified":"","tags":["attack.persistence","attack.t1136.003"],"technique_ids":["T1136.003"],"logsource":{"service":"exchange","product":"m365"},"falsepositives":["The creation of a new Federated domain is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a similar or different cloud provider."],"references":["https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf","https://us-cert.cisa.gov/ncas/alerts/aa21-008a","https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html","https://www.sygnia.co/golden-saml-advisory","https://o365blog.com/post/aadbackdoor/"],"source_path":"rules/cloud/m365/exchange/microsoft365_new_federated_domain_added_exchange.yml","source_sha256":"978880861725b27d1461809e494fcfbbd1149595e7bf8b7f1ad24e012b08a4b2","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/m365/exchange/microsoft365_new_federated_domain_added_exchange.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: New Federated Domain Added - Exchange\nid: 42127bdd-9133-474f-a6f1-97b6c08a4339\nrelated:\n    - id: 58f88172-a73d-442b-94c9-95eaed3cbb36\n      type: similar\nstatus: test\ndescription: Detects the addition of a new Federated Domain.\nreferences:\n    - https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf\n    - https://us-cert.cisa.gov/ncas/alerts/aa21-008a\n    - https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html\n    - https://www.sygnia.co/golden-saml-advisory\n    - https://o365blog.com/post/aadbackdoor/\nauthor: Splunk Threat Research Team (original rule), '@ionsor (rule)'\ndate: 2022-02-08\ntags:\n    - attack.persistence\n    - attack.t1136.003\nlogsource:\n    service: exchange\n    product: m365\ndetection:\n    selection:\n        eventSource: Exchange\n        eventName: 'Add-FederatedDomain'\n        status: success\n    condition: selection\nfalsepositives:\n    - The creation of a new Federated domain is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a similar or different cloud provider.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1136.003","id":"T1136.003","name":"Cloud Account","page":"techniques/enterprise/T1136.003/"}],"data_path":"data/detection-rules/42127bdd-9133-474f-a6f1-97b6c08a4339.json","kind":"sigma"}
