Log sources › saas:auth
saas:auth
Inverted view: what can be detected if this is the log you have. Identity Provider, SaaS
5
channels
5
analytics
5
techniques
21
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
API requests made with tokens not associated with expected user logins |
DC0007 Web Credential Usage | AN0722 | 1 |
Login, TokenGranted: Discovery actions tied to anomalous login sessions or tokens |
DC0067 Logon Session Creation | AN1130 | 1 |
LoginSuccess, APIKeyUse, AdminAction |
DC0067 Logon Session Creation | AN0020 | 1 |
Refresh token issuance or refresh token usage from new IPs or user agents |
DC0013 User Account Metadata | AN0501 | 1 |
signin_failed |
DC0002 User Account Authentication | AN1343 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1021.007 Cloud Services | lateral movement | 1 | 0 |
| T1110.003 Password Spraying | credential access | 0 | 0 |
| T1189 Drive-by Compromise | initial access | 3 | 21 |
| T1526 Cloud Service Discovery | discovery | 3 | 0 |
| T1606 Forge Web Credentials | credential access | 1 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 | Mapped |