1200KM / tag
signinlogs — logsource-service tag
24 related reference pages for logsource-service: signinlogs.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Account Disabled or Blocked for Sign in Attempts · sigma-rule
- Account Lockout · sigma-rule
- Application Using Device Code Authentication Flow · sigma-rule
- Applications That Are Using ROPC Authentication Flow · sigma-rule
- Authentications To Important Apps Using Single Factor Authentication · sigma-rule
- Azure AD Only Single Factor Authentication Required · sigma-rule
- Azure Unusual Authentication Interruption · sigma-rule
- Device Registration or Join Without MFA · sigma-rule
- Discovery Using AzureHound · sigma-rule
- Failed Authentications From Countries You Do Not Operate Out Of · sigma-rule
- Increased Failed Authentications Of Any Type · sigma-rule
- Login to Disabled Account · sigma-rule
- Measurable Increase Of Successful Authentications · sigma-rule
- Multifactor Authentication Denied · sigma-rule
- Multifactor Authentication Interrupted · sigma-rule
- Potential MFA Bypass Using Legacy Client Authentication · sigma-rule
- Sign-in Failure Due to Conditional Access Requirements Not Met · sigma-rule
- Sign-ins by Unknown Devices · sigma-rule
- Sign-ins from Non-Compliant Devices · sigma-rule
- Successful Authentications From Countries You Do Not Operate Out Of · sigma-rule
- Suspicious SignIns From A Non Registered Device · sigma-rule
- Use of Legacy Authentication Protocols · sigma-rule
- User Access Blocked by Azure Conditional Access · sigma-rule
- Users Authenticating To Other Azure AD Tenants · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.