kevmap

Log sources › azure:signinlogs

azure:signinlogs

Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite, SaaS, Windows

34
channels
35
analytics
33
techniques
56
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Abnormal sign-in from scripting tools (PowerShell, AADInternals) DC0067 Logon Session Creation AN0131 1
Add certificate credential, Update certificate credential DC0066 Active Directory Object Modification AN0674 1
ConsentGrant: Suspicious consent grants to non-approved or unknown applications DC0038 Application Log Content AN0301 1
Failed MFA attempts, unusual conditional access triggers, login attempts from unexpected IP ranges DC0067 Logon Session Creation AN0192 1
Failure Reason + UserPrincipalName DC0002 User Account Authentication AN1339 1
Graph API Query DC0083 Cloud Service Enumeration AN1616 1
Interactive/Non-Interactive Sign-In DC0002 User Account Authentication AN1087 1
InteractiveUser, NonInteractiveUser DC0067 Logon Session Creation AN1350 1
InteractiveUser, ServicePrincipalSignIn DC0067 Logon Session Creation AN1347 1
InteractiveUserLogin: Discovery behavior linked to privileged logins from atypical IP ranges DC0067 Logon Session Creation AN1128 1
Login from newly created account DC0002 User Account Authentication AN0899 1
Modify Conditional Access Policy DC0038 Application Log Content AN0544 1
Multiple MFA challenge requests without successful primary login DC0002 User Account Authentication AN0449 1
Operation=UserLogin DC0002 User Account Authentication AN0534 1
OperationName=SetDomainAuthentication OR Set-FederatedDomain DC0002 User Account Authentication AN0756 1
OperationName=SetDomainAuthentication OR Update-MsolFederatedDomain DC0064 Command Execution AN1260 1
Register PTA Agent or Modify AD FS trust DC0038 Application Log Content AN0815 1
Reset password or download key from portal DC0002 User Account Authentication AN1157 1
SAML-based login with anomalous issuer or NotOnOrAfter lifetime DC0088 Logon Session Metadata AN0418 1
SAML/OIDC tokens issued without corresponding MFA or password validation DC0006 Web Credential Creation AN0718 1
Sign-in activity DC0002 User Account Authentication AN1503 1
Sign-in logs DC0002 User Account Authentication AN1277 AN1524 2
Sign-in with unfamiliar location/device + portal navigation DC0002 User Account Authentication AN0809 1
SignIn: Sign-ins flagged as atypical (new geographic region, unfamiliar device id) shortly after correlated endpoint/browser compromise times DC0002 User Account Authentication AN0501 1
SigninSuccess DC0002 User Account Authentication AN1330 1
Success logs from high-risk accounts DC0002 User Account Authentication AN0295 1
Suspicious login to cloud mailbox system DC0067 Logon Session Creation AN0132 1
TokenIssuanceStart, TokenIssuanceSuccess DC0007 Web Credential Usage AN0956 1
TokenIssued, RefreshTokenUsed DC0007 Web Credential Usage AN0527 1
TokenIssued, TokenRenewed: Unexpected or anomalous token issuance events DC0002 User Account Authentication AN0496 1
Unusual Token Usage or Application Consent DC0002 User Account Authentication AN0642 1
UserLogin, ConditionalAccessPolicyEvaluated DC0067 Logon Session Creation AN1380 1
status = failure DC0002 User Account Authentication AN1265 1
unusual role assumption or elevation path DC0010 User Account Modification AN0978 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1078.004 Cloud Accountsstealth, persistence, privilege escalation, initial access411
T1087 Account Discoverydiscovery166
T1087.003 Email Accountdiscovery00
T1087.004 Cloud Accountdiscovery30
T1110 Brute Forcecredential access252
T1110.001 Password Guessingcredential access30
T1110.002 Password Crackingcredential access10
T1110.003 Password Sprayingcredential access00
T1110.004 Credential Stuffingcredential access00
T1114.002 Remote Email Collectioncollection01
T1119 Automated Collectioncollection51
T1136.003 Cloud Accountpersistence30
T1189 Drive-by Compromiseinitial access321
T1199 Trusted Relationshipinitial access21
T1212 Exploitation for Credential Accesscredential access54
T1213.002 Sharepointcollection00
T1484 Domain or Tenant Policy Modificationdefense impairment, privilege escalation10
T1484.002 Trust Modificationdefense impairment, privilege escalation20
T1526 Cloud Service Discoverydiscovery30
T1530 Data from Cloud Storagecollection02
T1538 Cloud Service Dashboarddiscovery00
T1548 Abuse Elevation Control Mechanismprivilege escalation244
T1550 Use Alternate Authentication Materiallateral movement50
T1550.001 Application Access Tokenlateral movement40
T1552 Unsecured Credentialscredential access134
T1556.006 Multi-Factor Authenticationdefense impairment, persistence, credential access30
T1556.007 Hybrid Identitydefense impairment, persistence, credential access00
T1566 Phishinginitial access146
T1566.002 Spearphishing Linkinitial access45
T1606 Forge Web Credentialscredential access10
T1606.002 SAML Tokenscredential access00
T1621 Multi-Factor Authentication Request Generationcredential access20
T1649 Steal or Forge Authentication Certificatescredential access110

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2010-2861Adobe ColdFusion T1119 Mapped
CVE-2012-0767Adobe Flash Player T1114.002 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 Mapped
CVE-2015-5119Adobe Flash Player T1566.002 Mapped
CVE-2015-8651Adobe Flash Player T1189 Mapped
CVE-2016-1019Adobe Flash Player T1189 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2020-0688Microsoft Exchange Server T1110 Mapped
CVE-2020-1472Microsoft Netlogon T1110 Mapped
CVE-2020-5902F5 BIG-IP T1552 Stale
CVE-2021-40449Microsoft Windows T1566 Mapped
CVE-2021-44515Zoho Desktop Central T1087 Mapped
CVE-2022-1388F5 BIG-IP T1548 Mapped
CVE-2022-22948VMware vCenter Server T1212 Mapped
CVE-2022-23131Zabbix Frontend T1548 Mapped
CVE-2022-34713Microsoft Windows T1566 Mapped
CVE-2022-41082Microsoft Exchange Server T1087 Mapped
CVE-2022-41128Microsoft Windows T1566 Mapped
CVE-2023-22952SugarCRM Multiple Products T1530 Stale
CVE-2023-2533PaperCut NG/MF T1566.002 Mapped
CVE-2023-27532Veeam Backup & Replication T1087 Mapped
CVE-2023-36884Microsoft Windows T1566 Stale
CVE-2023-43770Roundcube Webmail T1189 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1548 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1552 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 Mapped
CVE-2024-11182MDaemon Email Server T1566 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1552 Mapped
CVE-2024-21413Microsoft Office Outlook T1566.002 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1552 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1566.002 Mapped
CVE-2024-38112Microsoft Windows T1189 Mapped
CVE-2024-42009Roundcube Webmail T1566.002 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-49035Microsoft Partner Center T1530 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-5274Google Chromium V8 T1189 Mapped
CVE-2024-53704SonicWall SonicOS T1078.004 T1199 T1212 Mapped
CVE-2025-24054Microsoft Windows T1566 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-2783Google Chromium Mojo T1548 Mapped
CVE-2025-48927TeleMessage TM SGNL T1212 Mapped
CVE-2025-48928TeleMessage TM SGNL T1212 Mapped
CVE-2025-5419Google Chromium V8 T1189 Mapped
CVE-2025-6554Google Chromium V8 T1189 Mapped
CVE-2025-6558Google Chromium T1189 Mapped