Techniques › T1538 › AN0810
AN0810 Analytic 0810
Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects login to admin consoles (e.g., Microsoft 365 Admin Center) from unrecognized users, devices, or geolocations followed by non-API data review or configuration read actions that suggest GUI dashboard use.</p>
- Detects
- T1538 Cloud Service Dashboard
- Part of
- DET0291 Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| m365:signinlogs | UserLoginSuccess | DC0002 User Account Authentication |
| m365:unified | ViewAdminReport | DC0067 Logon Session Creation |
| m365:unified | Read-only configuration review from GUI | DC0038 Application Log Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AdminRoleList | Roles allowed to access dashboard views |
DashboardNavigationSequence | Pageview paths or clickstreams indicating use of GUI admin console |
GeoLocationRisk | List of high-risk regions or unexpected geos |