Techniques
Sample rules
Roles Assigned Outside PIM
- source: sigma
- technicques:
- t1078
Description
Identifies when a privilege role assignment has taken place outside of PIM and may indicate an attack.
Detection logic
condition: selection
selection:
riskEventType: rolesAssignedOutsidePrivilegedIdentityManagementAlertConfiguration