{"id":"4d78a000-ab52-4564-88a5-7ab5242b20c7","title":"Change to Authentication Method","description":"Change to authentication method could be an indicator of an attacker adding an auth method to the account so they can have continued access.","author":"AlertIQ","status":"test","level":"medium","date":"2021-10-10","modified":"2022-12-25","tags":["attack.privilege-escalation","attack.credential-access","attack.defense-impairment","attack.t1556","attack.persistence","attack.t1098"],"technique_ids":["T1098","T1556"],"logsource":{"product":"azure","service":"auditlogs"},"falsepositives":["Unknown"],"references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts"],"source_path":"rules/cloud/azure/audit_logs/azure_change_to_authentication_method.yml","source_sha256":"b5f0dda93aa123d14cb73c0f5bf81be94be2b4df18a1bba211db8db4e16eb662","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/azure/audit_logs/azure_change_to_authentication_method.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Change to Authentication Method\nid: 4d78a000-ab52-4564-88a5-7ab5242b20c7\nstatus: test\ndescription: Change to authentication method could be an indicator of an attacker adding an auth method to the account so they can have continued access.\nreferences:\n    - https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts\nauthor: AlertIQ\ndate: 2021-10-10\nmodified: 2022-12-25\ntags:\n    - attack.privilege-escalation\n    - attack.credential-access\n    - attack.defense-impairment\n    - attack.t1556\n    - attack.persistence\n    - attack.t1098\nlogsource:\n    product: azure\n    service: auditlogs\ndetection:\n    selection:\n        LoggedByService: 'Authentication Methods'\n        Category: 'UserManagement'\n        OperationName: 'User registered security info'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1098","id":"T1098","name":"Account Manipulation","page":"techniques/enterprise/T1098/"},{"key":"enterprise/T1556","id":"T1556","name":"Modify Authentication Process","page":"techniques/enterprise/T1556/"}],"data_path":"data/detection-rules/4d78a000-ab52-4564-88a5-7ab5242b20c7.json","kind":"sigma"}
