kevmap

TechniquesT1078 › AN1546

AN1546 Analytic 1546

Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of valid account abuse in IdP logs via geographic anomalies, impossible travel, risky sign-ins, and multiple MFA attempts or failures.</p>
Detects
T1078 Valid Accounts
Part of
DET0560 Detection of Valid Account Abuse Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
saas:oktaSign-in logs / audit eventsDC0002 User Account Authentication

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MFAFailureCountThreshold of failed MFA attempts before alerting.
RiskScoreThresholdCustom threshold based on calculated identity risk.
IPGeoVelocityDetect impossible travel (logins from two distant geolocations within short time).

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-13608Citrix StoreFront ServerMapped
CVE-2021-20035SonicWall SMA100 AppliancesMapped
CVE-2021-22894Ivanti Pulse Connect SecureMapped
CVE-2021-22899Ivanti Pulse Connect SecureMapped
CVE-2021-36934Microsoft WindowsMapped
CVE-2021-41379Microsoft WindowsMapped
CVE-2021-42321Microsoft ExchangeMapped
CVE-2022-1040Sophos FirewallMapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-21919Microsoft WindowsMapped
CVE-2022-21999Microsoft WindowsMapped
CVE-2022-22047Microsoft WindowsMapped
CVE-2022-22718Microsoft WindowsMapped
CVE-2022-22948VMware vCenter ServerMapped
CVE-2022-23131Zabbix FrontendMapped
CVE-2022-24521Microsoft WindowsMapped
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26904Microsoft WindowsMapped
CVE-2022-37969Microsoft WindowsMapped
CVE-2022-41073Microsoft WindowsMapped
CVE-2022-41082Microsoft Exchange ServerMapped
CVE-2022-41125Microsoft WindowsMapped
CVE-2023-20109Cisco IOS and IOS XEMapped
CVE-2023-20118Cisco Small Business RV Series RoutersMapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat DefenseMapped
CVE-2023-20273Cisco Cisco IOS XE Web UIMapped
CVE-2023-20867VMware ToolsMapped
CVE-2023-21674Microsoft WindowsMapped
CVE-2023-22515Atlassian Confluence Data Center and ServerMapped
CVE-2023-22952SugarCRM Multiple ProductsStale
CVE-2023-23397Microsoft OfficeMapped
CVE-2023-27524Apache SupersetMapped
CVE-2023-28229Microsoft Windows CNG Key Isolation ServiceMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-39780ASUS RT-AX55 RoutersMapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business SecurityMapped
CVE-2023-46805Ivanti Connect Secure and Policy SecureMapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2024-20399Cisco NX-OSMapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and NeuronsMapped
CVE-2024-37085VMware ESXiMapped
CVE-2024-55591Fortinet FortiOS and FortiProxyMapped
CVE-2024-57968Advantive VeraCoreMapped
CVE-2025-24016Wazuh Wazuh ServerMapped
CVE-2025-31161CrushFTP CrushFTPMapped