Cloud identity and token theft detection pack — Entra ID and Okta
Four Sigma rules for the cloud identity attacks that actually land: illicit consent grants, authentication methods added after a risky sign-in, help-desk MFA resets, and session tokens replayed from a second address.
A companion to the persistence and execution pack, aimed at the half of modern
intrusions that never touch an endpoint.
The common thread across all four rules is that the password is not the
control that failed. In each case multi-factor authentication was present and
satisfied, and the operator worked around it: by holding a token that was minted
after the factor was checked, by registering a factor of their own, or by
persuading somebody to reset the one that existed. Detection has to sit on those
events rather than on the sign-in.
Read the false-positive note on every rule before you deploy it. Two of these
are close to useless without local tuning, and the notes say which two and what
tuning they need. A rule shipped without that context gets switched off in a
fortnight, which is worse than never having deployed it.