Techniques › T1684 › AN2034
AN2034 Analytic 2034
SaaS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.</p>
- Detects
- T1684 Social Engineering
- Part of
- DET0899 Detect Social Engineering
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| saas:okta | user.account.reset_password; user.mfa.factor.activate; app.oauth2.authorize | DC0002 User Account Authentication |
| saas:slack | xternal DM or workspace invite preceding credential or approval actions | DC0038 Application Log Content |
| saas:zoom | Unexpected contact interaction preceding follow-on admin requests | DC0038 Application Log Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
RequesterNoveltyDays | How long since requestor last interacted with user |
GeoVelocityThreshold | Distance/time anomaly for follow-on login |
AfterHoursDefinition | Organization-specific off-hours period |