← Library
yara-lApache-2.0from chronicle/detection-rules

entra_id_admin_login_activity_to_uncommon_mscloud_apps

Detects Azure AD admin login activity to apps other than a defined list of first party MS Cloud Apps. Note that Azure Active Directory PowerShell and custom Azure apps are not in this list by default

Quality
98
FP risk
Forks
0
Views
0
ATT&CK techniques
Rule source🔒 locked
🔒

Sign in to view the rule source

Free accounts can view the source for the top-ranked rules. Create one in seconds — no credit card required.

Sign in →