Skip to content

Applications Rules

3 detection rules in this category.

RuleSeverityMITRESource
App role assigned to service principalHighT1098.001AuditLog
Application credentials addedHighT1098.001AuditLog
OAuth app consent grantedHighT1098.001AuditLog

App role assigned to service principal

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1098.001 (Persistence)

Application permission assigned - check scope

Conditions
  • Match: all
  • Operation Equals Add app role assignment to service principal

Application credentials added

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1098.001 (Persistence)

New credentials added to application - verify legitimacy

Conditions
  • Match: all
  • Operation Equals Add service principal credentials

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1098.001 (Persistence)

OAuth application consent granted - check for illicit consent

Conditions
  • Match: all
  • Operation Equals Consent to application