kevmap

TechniquesT1684 › AN2034

AN2034 Analytic 2034

SaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.</p>
Detects
T1684 Social Engineering
Part of
DET0899 Detect Social Engineering

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
saas:oktauser.account.reset_password; user.mfa.factor.activate; app.oauth2.authorizeDC0002 User Account Authentication
saas:slackxternal DM or workspace invite preceding credential or approval actionsDC0038 Application Log Content
saas:zoomUnexpected contact interaction preceding follow-on admin requestsDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
RequesterNoveltyDaysHow long since requestor last interacted with user
GeoVelocityThresholdDistance/time anomaly for follow-on login
AfterHoursDefinitionOrganization-specific off-hours period