{"id":"58f88172-a73d-442b-94c9-95eaed3cbb36","title":"New Federated Domain Added","description":"Detects the addition of a new Federated Domain.","author":"Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule)","status":"test","level":"medium","date":"2023-09-18","modified":"","tags":["attack.privilege-escalation","attack.defense-impairment","attack.t1484.002"],"technique_ids":["T1484.002"],"logsource":{"service":"audit","product":"m365"},"falsepositives":["The creation of a new Federated domain is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a similar or different cloud provider."],"references":["https://research.splunk.com/cloud/e155876a-6048-11eb-ae93-0242ac130002/","https://o365blog.com/post/aadbackdoor/"],"source_path":"rules/cloud/m365/audit/microsoft365_new_federated_domain_added_audit.yml","source_sha256":"c1730f901e0095c8b548c90c747832329e08a2d15872400cb84abc6d727b89d7","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/m365/audit/microsoft365_new_federated_domain_added_audit.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: New Federated Domain Added\nid: 58f88172-a73d-442b-94c9-95eaed3cbb36\nrelated:\n    - id: 42127bdd-9133-474f-a6f1-97b6c08a4339\n      type: similar\nstatus: test\ndescription: Detects the addition of a new Federated Domain.\nreferences:\n    - https://research.splunk.com/cloud/e155876a-6048-11eb-ae93-0242ac130002/\n    - https://o365blog.com/post/aadbackdoor/\nauthor: Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule)\ndate: 2023-09-18\ntags:\n    - attack.privilege-escalation\n    - attack.defense-impairment\n    - attack.t1484.002\nlogsource:\n    service: audit\n    product: m365\ndetection:\n    selection_domain:\n        Operation|contains: 'domain'\n    selection_operation:\n        Operation|contains:\n            - 'add'\n            - 'new'\n    condition: all of selection_*\nfalsepositives:\n    - The creation of a new Federated domain is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a similar or different cloud provider.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1484.002","id":"T1484.002","name":"Trust Modification","page":"techniques/enterprise/T1484.002/"}],"data_path":"data/detection-rules/58f88172-a73d-442b-94c9-95eaed3cbb36.json","kind":"sigma"}
