Techniques › T1606.002 › AN0422
AN0422 Analytic 0422
Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Forged SAML tokens may be leveraged to access O365 apps such as Outlook or SharePoint. Defenders should monitor for token replay across multiple clients or access attempts to privileged mailboxes without prior interactive login.</p>
- Detects
- T1606.002 SAML Tokens
- Part of
- DET0148 Detection Strategy for Forged SAML Tokens
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| m365:exchange | Mailbox access using SAML token without corresponding MFA event | DC0007 Web Credential Usage |
| m365:sharepoint | File access with forged or anomalous SAML claims | DC0067 Logon Session Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ReplayDetectionThreshold | Number of times a token is reused within short timeframe. |