kevmap

TechniquesT1212 › AN0496

AN0496 Analytic 0496

Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects exploitation of vulnerabilities in cloud identity providers (IdPs) such as Azure AD or Okta for credential access. Defender perspective includes anomalous token creation or renewal, authentication bypass events, and API abuse to mint unauthorized tokens. Correlation highlights exploitation attempts tied to absent or inconsistent audit logs.</p>
Detects
T1212 Exploitation for Credential Access
Part of
DET0174 Detection Strategy for Exploitation for Credential Access

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
azure:signinlogsTokenIssued, TokenRenewed: Unexpected or anomalous token issuance eventsDC0002 User Account Authentication
m365:unifiedConsentGranted: Abuse of application integrations to mint tokens bypassing MFADC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TokenAnomalyThresholdThreshold for anomalous token creation or renewal before alerting.
MonitoredAppIntegrationsApplications with privileged access that should be tightly monitored for misuse.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-22948VMware vCenter ServerMapped
CVE-2024-53704SonicWall SonicOSMapped
CVE-2025-48927TeleMessage TM SGNLMapped
CVE-2025-48928TeleMessage TM SGNLMapped