Social Engineering T1684

Tactic: Stealth

Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instructions (i.e., introduction of malicious payloads or software), while minimizing technical indicators.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (9 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
azure.signinlogs.properties.authentication_processing_details1contains 1user_impersonation
azure.signinlogs.properties.conditional_access_status1eq 1notapplied
azure.signinlogs.properties.device_detail.device_id1eq 1
azure.signinlogs.properties.token_issuer_type1eq 1azuread
azure.signinlogs.properties.token_protection_status_details.sign_in_session_status1eq 1unbound
azure_ad::authentication_requirement1eq 1singlefactorauthentication
azure_ad::user_type1eq 1member
data_stream.dataset1eq 1azure.signinlogs
event.outcome1eq 1success

Top indicator values (8 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
azure.signinlogs.properties.authentication_processing_detailscontains
user_impersonation
1
azure.signinlogs.properties.conditional_access_statuseq
notapplied
1
azure.signinlogs.properties.token_issuer_typeeq
azuread
12
azure.signinlogs.properties.token_protection_status_details.sign_in_session_statuseq
unbound
14
azure_ad::authentication_requirementeq
singlefactorauthentication
18
azure_ad::user_typeeq
member
111
data_stream.dataseteq
azure.signinlogs
136
event.outcomeeq
success
1375

Exclusions (31 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
aws::userAgentwildcard
Microsoft*Authentication*iPhone*
1
aws::userAgentwildcard
Mozilla*PKeyAuth/1.0
1
azure.signinlogs.properties.authentication_processing_detailscontains
restricted_user_impersonation
1
azure.signinlogs.properties.client_app_usedeq
browser
1
azure.signinlogs.properties.device_detail.is_complianteq
true
1
azure.signinlogs.properties.device_detail.is_managedeq
true
1
azure.signinlogs.properties.device_detail.operating_systemeq
windows
1
azure.signinlogs.properties.device_detail.operating_systemstarts_with
Android
1
azure.signinlogs.properties.device_detail.operating_systemstarts_with
Ios
1
azure.signinlogs.properties.device_detail.operating_systemstarts_with
Windows
1
azure.signinlogs.properties.device_detail.trust_typein
azure ad joined
1
azure.signinlogs.properties.device_detail.trust_typein
hybrid azure ad joined
1
azure.signinlogs.properties.incoming_token_typeeq
none
1
azure_ad::app_ideq
00000002-0000-0ff1-ce00-000000000000
1
azure_ad::app_ideq
5f00fd34-f302-417f-81ef-1adda179d8fd
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Azure

Domain: Cloud

Elastic 1 rule