Skip to content

AAD SignIns Insights #210

@piaudonn

Description

@piaudonn

I wonder if there would be an interest for such a module. It's essentially a similar concept of what we have for analysts in the entity page available for automation and a bit of what we have in UEBA.

Takes a user and return stats such as:

  • Last successful logon data (timestamp + other metadata)
  • Last failed logon data
  • Usual user-agent-string data
  • Usual contries/IPs

If there is a cloud-logon-session present in the entities (case of an AAD Protection alert), return all the info about this particular login.

That last one maybe could be added to the AAD Risk Module instead.

Metadata

Metadata

Assignees

Labels

new moduleNew automation module

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions