Log sources › azure:signinlogs
azure:signinlogs
Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite, SaaS, Windows
34
channels
35
analytics
33
techniques
56
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Abnormal sign-in from scripting tools (PowerShell, AADInternals) |
DC0067 Logon Session Creation | AN0131 | 1 |
Add certificate credential, Update certificate credential |
DC0066 Active Directory Object Modification | AN0674 | 1 |
ConsentGrant: Suspicious consent grants to non-approved or unknown applications |
DC0038 Application Log Content | AN0301 | 1 |
Failed MFA attempts, unusual conditional access triggers, login attempts from unexpected IP ranges |
DC0067 Logon Session Creation | AN0192 | 1 |
Failure Reason + UserPrincipalName |
DC0002 User Account Authentication | AN1339 | 1 |
Graph API Query |
DC0083 Cloud Service Enumeration | AN1616 | 1 |
Interactive/Non-Interactive Sign-In |
DC0002 User Account Authentication | AN1087 | 1 |
InteractiveUser, NonInteractiveUser |
DC0067 Logon Session Creation | AN1350 | 1 |
InteractiveUser, ServicePrincipalSignIn |
DC0067 Logon Session Creation | AN1347 | 1 |
InteractiveUserLogin: Discovery behavior linked to privileged logins from atypical IP ranges |
DC0067 Logon Session Creation | AN1128 | 1 |
Login from newly created account |
DC0002 User Account Authentication | AN0899 | 1 |
Modify Conditional Access Policy |
DC0038 Application Log Content | AN0544 | 1 |
Multiple MFA challenge requests without successful primary login |
DC0002 User Account Authentication | AN0449 | 1 |
Operation=UserLogin |
DC0002 User Account Authentication | AN0534 | 1 |
OperationName=SetDomainAuthentication OR Set-FederatedDomain |
DC0002 User Account Authentication | AN0756 | 1 |
OperationName=SetDomainAuthentication OR Update-MsolFederatedDomain |
DC0064 Command Execution | AN1260 | 1 |
Register PTA Agent or Modify AD FS trust |
DC0038 Application Log Content | AN0815 | 1 |
Reset password or download key from portal |
DC0002 User Account Authentication | AN1157 | 1 |
SAML-based login with anomalous issuer or NotOnOrAfter lifetime |
DC0088 Logon Session Metadata | AN0418 | 1 |
SAML/OIDC tokens issued without corresponding MFA or password validation |
DC0006 Web Credential Creation | AN0718 | 1 |
Sign-in activity |
DC0002 User Account Authentication | AN1503 | 1 |
Sign-in logs |
DC0002 User Account Authentication | AN1277 AN1524 | 2 |
Sign-in with unfamiliar location/device + portal navigation |
DC0002 User Account Authentication | AN0809 | 1 |
SignIn: Sign-ins flagged as atypical (new geographic region, unfamiliar device id) shortly after correlated endpoint/browser compromise times |
DC0002 User Account Authentication | AN0501 | 1 |
SigninSuccess |
DC0002 User Account Authentication | AN1330 | 1 |
Success logs from high-risk accounts |
DC0002 User Account Authentication | AN0295 | 1 |
Suspicious login to cloud mailbox system |
DC0067 Logon Session Creation | AN0132 | 1 |
TokenIssuanceStart, TokenIssuanceSuccess |
DC0007 Web Credential Usage | AN0956 | 1 |
TokenIssued, RefreshTokenUsed |
DC0007 Web Credential Usage | AN0527 | 1 |
TokenIssued, TokenRenewed: Unexpected or anomalous token issuance events |
DC0002 User Account Authentication | AN0496 | 1 |
Unusual Token Usage or Application Consent |
DC0002 User Account Authentication | AN0642 | 1 |
UserLogin, ConditionalAccessPolicyEvaluated |
DC0067 Logon Session Creation | AN1380 | 1 |
status = failure |
DC0002 User Account Authentication | AN1265 | 1 |
unusual role assumption or elevation path |
DC0010 User Account Modification | AN0978 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2010-2861 | Adobe ColdFusion | T1119 | Mapped |
| CVE-2012-0767 | Adobe Flash Player | T1114.002 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1566.002 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1110 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1110 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1552 | Stale |
| CVE-2021-40449 | Microsoft Windows | T1566 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1087 | Mapped |
| CVE-2022-1388 | F5 BIG-IP | T1548 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1212 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1548 | Mapped |
| CVE-2022-34713 | Microsoft Windows | T1566 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1087 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1566 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1530 | Stale |
| CVE-2023-2533 | PaperCut NG/MF | T1566.002 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1087 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1566 | Stale |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1548 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1552 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1566 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-20439 | Cisco Smart Licensing Utility | T1552 | Mapped |
| CVE-2024-21413 | Microsoft Office Outlook | T1566.002 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1552 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1566.002 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1566.002 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1530 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1078.004 T1199 T1212 | Mapped |
| CVE-2025-24054 | Microsoft Windows | T1566 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1548 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1212 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1212 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 | Mapped |