kevmap

TechniquesT1606 › AN0722

AN0722 Analytic 0722

SaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>SaaS platforms may show forged credentials as unusual API keys, tokens, or session cookies being used without corresponding authentication. Correlated patterns include simultaneous valid sessions from multiple geographies, unusual API calls with new tokens, or bypass of expected MFA enforcement.</p>
Detects
T1606 Forge Web Credentials
Part of
DET0260 Detection Strategy for Forged Web Credentials

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedSession creation without MFA or login eventDC0006 Web Credential Creation
saas:authAPI requests made with tokens not associated with expected user loginsDC0007 Web Credential Usage

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
GeoLocationAlertsTrigger on logins from unusual or high-risk geographies.
TokenReplayThresholdDetect multiple simultaneous uses of the same forged credential.