Cloud identity and token theft detection pack — Entra ID and Okta

Four Sigma rules for the cloud identity attacks that actually land: illicit consent grants, authentication methods added after a risky sign-in, help-desk MFA resets, and session tokens replayed from a second address.

A companion to the persistence and execution pack, aimed at the half of modern intrusions that never touch an endpoint.

The common thread across all four rules is that the password is not the control that failed. In each case multi-factor authentication was present and satisfied, and the operator worked around it: by holding a token that was minted after the factor was checked, by registering a factor of their own, or by persuading somebody to reset the one that existed. Detection has to sit on those events rather than on the sign-in.

Read the false-positive note on every rule before you deploy it. Two of these are close to useless without local tuning, and the notes say which two and what tuning they need. A rule shipped without that context gets switched off in a fortnight, which is worse than never having deployed it.