kevmap

TechniquesT1119 › AN0534

AN0534 Analytic 0534

SaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Suspicious sign-ins to Graph API or sensitive resources using non-browser scripting agents (e.g., Python, PowerShell), often for programmatic access to mailbox or OneDrive content.</p>
Detects
T1119 Automated Collection
Part of
DET0186 Automated File and API Collection Detection Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
azure:signinlogsOperation=UserLoginDC0002 User Account Authentication

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
UserAgentFilterFilter for scripting agents (e.g., Python, PowerShell) which may vary by org.
ExpectedClientIPListSet of known internal or managed IPs to filter benign automation.
DevicePropertiesExpected managed device profiles used to detect unmanaged devices.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2010-2861Adobe ColdFusionMapped