kevmap

TechniquesT1538 › AN0810

AN0810 Analytic 0810

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects login to admin consoles (e.g., Microsoft 365 Admin Center) from unrecognized users, devices, or geolocations followed by non-API data review or configuration read actions that suggest GUI dashboard use.</p>
Detects
T1538 Cloud Service Dashboard
Part of
DET0291 Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:signinlogsUserLoginSuccessDC0002 User Account Authentication
m365:unifiedViewAdminReportDC0067 Logon Session Creation
m365:unifiedRead-only configuration review from GUIDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AdminRoleListRoles allowed to access dashboard views
DashboardNavigationSequencePageview paths or clickstreams indicating use of GUI admin console
GeoLocationRiskList of high-risk regions or unexpected geos