kevmap

TechniquesT1671 › AN1488

AN1488 Analytic 1488

SaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects anomalous SaaS application integration activity across environments such as Slack, Salesforce, or other enterprise SaaS services. Focus is on unauthorized app additions, unusual permission grants, and persistence through service principal tokens.</p>
Detects
T1671 Cloud Application Integration
Part of
DET0539 Detection Strategy for Cloud Application Integration

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
saas:integrationNew or modified third-party application integrations with elevated permissionsDC0069 Cloud Service Modification
saas:auditApplication added or consent granted: Integration persisting after original user disabledDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AppWhitelistDefines approved SaaS integrations for the enterprise; deviations indicate suspicious persistence.
ConsentDelegationPolicyThreshold for which users can self-consent integrations; lowering this may reduce false positives.