New Federated Domain Added

 Original Source: [Sigma source]
Title: New Federated Domain Added
Status: test
Description:Detects the addition of a new Federated Domain.
References:
  -https://research.splunk.com/cloud/e155876a-6048-11eb-ae93-0242ac130002/
  -https://o365blog.com/post/aadbackdoor/
Author: Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule)
Date: 2023-09-18
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.defense-impairment'
  • -'attack.t1484.002'
Logsource:
  • service: audit
  • product: m365
Detection:
  selection_domain:
    Operation|contains: 'domain'
  selection_operation:
    Operation|contains:
      -'add'
      -'new'

  condition:all of selection_*
Falsepositives:
  -The creation of a new Federated domain is not necessarily malicious, however these events need to be followed closely, as it may indicate federated credential abuse or backdoor via federated identities at a similar or different cloud provider.
Level: medium