Detecting Suspicious Activity From SSO-Connected Third-Party Platforms
Weaknesses in third-party platforms connected to your SSO can let attackers gain access as employees. These detections help spot misuse.
Insights
Articles in Detection & Response.
Weaknesses in third-party platforms connected to your SSO can let attackers gain access as employees. These detections help spot misuse.
Rogue or manipulated AI agents reveal themselves through activity outside their expected scope. These detections focus on egress, unexpected data access and...
Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.
Identity platform flaws — and attackers who abuse provisioning — can create or modify accounts in ways that look automated. These detections focus on...
AI agents escaping containment or misusing access produce telemetry you can watch. These detections focus on agent identities, network egress and shared...
Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.
Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.
Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.
When attackers move at machine speed, detection must focus on early, high-signal events and trigger automatic containment. These detections target fast...
Package ecosystem worms leave signals across developer endpoints, code platforms and cloud logs. These detections help spot an infection and its use of...
When identity platform flaws limit logging of the initial access, you can still detect what attackers do next. These detections focus on cross-tenant...
Stolen OAuth tokens used for data theft show up as bulk API activity from integrations. These detections help catch it.
SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and...
Prompt injection against AI assistants is hard to detect directly. You can, however, monitor for the conditions that make it dangerous and for signs of misuse.
After help desk social engineering, attackers typically reset MFA, register their own method and sign in. These detections connect those events.
Supply-chain attacks on CI/CD dependencies often reveal themselves in workflow behavior and logs. These detections help spot compromised actions and secret...
When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...
Stolen AWS session tokens let attackers act as a legitimate user without signing in. Detection focuses on where and how sessions are used.
Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.
Stolen API keys for remote support tools grant access without user sign-ins. These detections focus on unusual key use and remote sessions.
Credential theft from exposed configuration files leads to predictable AWS activity. These detections target the patterns seen in .env-based extortion...
Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.
Compromised open-source packages are hard to detect by behavior — they're designed to look legitimate. Detection relies on inventory, threat intelligence...
Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.