LoFP
/
T1535
T1535
Title
Tags
a user with successful authentication events from different ips may also represent the legitimate use of more than one device. filter as needed and/or customize the threshold to fit your environment.
t1110
t1110.001
T1110.003
T1535
t1586
azure tenant
aws account
splunk
it's possible that a user has unknowingly started an instance in a new region. please verify that this activity is legitimate.
T1535
aws instance
cloud compute instance
splunk
when a legitimate new user logins for the first time, this activity will be detected. check how old the account is and verify that the user activity is legitimate.
t1078.004
T1535
t1552
t1586
t1586.003
aws instance
splunk