Techniques
Sample rules
Unfamiliar Sign-In Properties
- source: sigma
- technicques:
- t1078
Description
Detects sign-in with properties that are unfamiliar to the user. The detection considers past sign-in history to look for anomalous sign-ins.
Detection logic
condition: selection
selection:
riskEventType: unfamiliarFeatures