MITRE ATT&CK technique
Trusted Relationship detection rulesT1199
Trusted Relationship (T1199) is a MITRE ATT&CK technique in the Initial Access tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1199 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target m365, okta.
Tactic
Microsoft 365 - User Restricted from Sending Email
mediumDetects when a Security Compliance Center reported a user who exceeded sending limits of the service policies and because of this has been restricted from sending email.
m365
Okta Session Impersonation Granted From Untrusted Domain
mediumDetects Okta session impersonation grant event where a user is granted the ability to impersonate another user's session. This event type "user.session.impersonation.grant" signifies that someone has been given temporary access to act on behalf of another user account. Threat actors may abuse this functionality to escalate privileges, access sensitive resources, or perform unauthorized actions while appearing to be the impersonated user. Legitimate use cases are typically limited to Okta support scenarios or authorized administrative troubleshooting.
okta