Skip to content

Applications Rules

3 detection rules in this category.

RuleSeverityMITRESource
App consent grantedHighT1098.001AuditLog
App role assigned to service principalHighT1098.001AuditLog
Application credentials addedHighT1098.001AuditLog

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1098.001 (Persistence)

Application consent granted - check for illicit consent

Conditions
  • Match: all
  • Operation Equals Consent to application

App role assigned to service principal

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1098.001 (Persistence)

Application permission assigned - check scope

Conditions
  • Match: all
  • Operation Equals Add app role assignment to service principal

Application credentials added

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1098.001 (Persistence)

New credentials added to application (secret or certificate)

Conditions
  • Match: all
  • Operation Contains Certificates and secrets management