Techniques › T1212 › AN0496
AN0496 Analytic 0496
Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects exploitation of vulnerabilities in cloud identity providers (IdPs) such as Azure AD or Okta for credential access. Defender perspective includes anomalous token creation or renewal, authentication bypass events, and API abuse to mint unauthorized tokens. Correlation highlights exploitation attempts tied to absent or inconsistent audit logs.</p>
- Detects
- T1212 Exploitation for Credential Access
- Part of
- DET0174 Detection Strategy for Exploitation for Credential Access
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| azure:signinlogs | TokenIssued, TokenRenewed: Unexpected or anomalous token issuance events | DC0002 User Account Authentication |
| m365:unified | ConsentGranted: Abuse of application integrations to mint tokens bypassing MFA | DC0038 Application Log Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
TokenAnomalyThreshold | Threshold for anomalous token creation or renewal before alerting. |
MonitoredAppIntegrations | Applications with privileged access that should be tightly monitored for misuse. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2022-22948 | VMware vCenter Server | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | Mapped |