Back
Id16f26d2c-6296-490b-af4f-b30bcf1c4461
RulenameRed Sift - MFA disabled on account
DescriptionThis query searches for authentication events where MFA has been disabled on an account, which may indicate account takeover activity, weakened account protections, or unauthorized administrative changes.
SeverityHigh
TacticsDefenseEvasion
TechniquesT1556
Required data connectorsRedSiftPush
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Red%20Sift/Analytic%20Rules/RedSiftMFADisabled.yaml
Version1.0.0
Arm template16f26d2c-6296-490b-af4f-b30bcf1c4461.json
Deploy To Azure
RedSiftAuth_CL
| extend
    ActivityName = tostring(column_ifexists("ActivityName", "")),
    UserEmail = tostring(column_ifexists("UserEmail", "")),
    ActorUserEmail = tostring(column_ifexists("ActorUserEmail", "")),
    SrcIp = tostring(column_ifexists("SrcIp", "")),
    HttpUserAgent = tostring(column_ifexists("HttpUserAgent", "")),
    ServiceName = tostring(column_ifexists("ServiceName", "")),
    Severity = tostring(column_ifexists("Severity", "")),
    UserUid = tostring(column_ifexists("UserUid", "")),
    ActorUserUid = tostring(column_ifexists("ActorUserUid", ""))
| where ActivityName =~ "MFA Disabled"
| where isnotempty(UserEmail) or isnotempty(ActorUserEmail)
| extend TargetAccount = iff(isnotempty(UserEmail), UserEmail, ActorUserEmail)
| project
    TimeGenerated,
    TargetAccount,
    UserEmail,
    ActorUserEmail,
    SrcIp,
    HttpUserAgent,
    ServiceName,
    ActivityName,
    Severity,
    UserUid,
    ActorUserUid
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: P1D
    enabled: true
    reopenClosedIncident: false
    matchingMethod: Selected
    groupByEntities:
    - Account
  createIncident: true
name: Red Sift - MFA disabled on account
suppressionDuration: PT1H
suppressionEnabled: false
triggerOperator: gt
query: |
  RedSiftAuth_CL
  | extend
      ActivityName = tostring(column_ifexists("ActivityName", "")),
      UserEmail = tostring(column_ifexists("UserEmail", "")),
      ActorUserEmail = tostring(column_ifexists("ActorUserEmail", "")),
      SrcIp = tostring(column_ifexists("SrcIp", "")),
      HttpUserAgent = tostring(column_ifexists("HttpUserAgent", "")),
      ServiceName = tostring(column_ifexists("ServiceName", "")),
      Severity = tostring(column_ifexists("Severity", "")),
      UserUid = tostring(column_ifexists("UserUid", "")),
      ActorUserUid = tostring(column_ifexists("ActorUserUid", ""))
  | where ActivityName =~ "MFA Disabled"
  | where isnotempty(UserEmail) or isnotempty(ActorUserEmail)
  | extend TargetAccount = iff(isnotempty(UserEmail), UserEmail, ActorUserEmail)
  | project
      TimeGenerated,
      TargetAccount,
      UserEmail,
      ActorUserEmail,
      SrcIp,
      HttpUserAgent,
      ServiceName,
      ActivityName,
      Severity,
      UserUid,
      ActorUserUid
queryFrequency: 1h
description: |
  This query searches for authentication events where MFA has been disabled on an account, which may indicate account takeover activity, weakened account protections, or unauthorized administrative changes.
id: 16f26d2c-6296-490b-af4f-b30bcf1c4461
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
customDetails:
  ServiceName: ServiceName
  UserAgent: HttpUserAgent
  ActivityName: ActivityName
  ActorUserEmail: ActorUserEmail
status: Available
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: High
requiredDataConnectors:
- connectorId: RedSiftPush
  dataTypes:
  - RedSiftAuth_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Red%20Sift/Analytic%20Rules/RedSiftMFADisabled.yaml
alertDetailsOverride:
  alertDescriptionFormat: 'MFA was disabled for {{TargetAccount}}. Actor: {{ActorUserEmail}}. Source IP: {{SrcIp}}.'
  alertDisplayNameFormat: RedSift - MFA Disabled for {{TargetAccount}}
relevantTechniques:
- T1556
tactics:
- DefenseEvasion
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: TargetAccount
  entityType: Account
- fieldMappings:
  - identifier: Address
    columnName: SrcIp
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/16f26d2c-6296-490b-af4f-b30bcf1c4461')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/16f26d2c-6296-490b-af4f-b30bcf1c4461')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "MFA was disabled for {{TargetAccount}}. Actor: {{ActorUserEmail}}. Source IP: {{SrcIp}}.",
          "alertDisplayNameFormat": "RedSift - MFA Disabled for {{TargetAccount}}"
        },
        "alertRuleTemplateName": "16f26d2c-6296-490b-af4f-b30bcf1c4461",
        "customDetails": {
          "ActivityName": "ActivityName",
          "ActorUserEmail": "ActorUserEmail",
          "ServiceName": "ServiceName",
          "UserAgent": "HttpUserAgent"
        },
        "description": "This query searches for authentication events where MFA has been disabled on an account, which may indicate account takeover activity, weakened account protections, or unauthorized administrative changes.\n",
        "displayName": "Red Sift - MFA disabled on account",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "TargetAccount",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIp",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByEntities": [
              "Account"
            ],
            "lookbackDuration": "P1D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Red%20Sift/Analytic%20Rules/RedSiftMFADisabled.yaml",
        "query": "RedSiftAuth_CL\n| extend\n    ActivityName = tostring(column_ifexists(\"ActivityName\", \"\")),\n    UserEmail = tostring(column_ifexists(\"UserEmail\", \"\")),\n    ActorUserEmail = tostring(column_ifexists(\"ActorUserEmail\", \"\")),\n    SrcIp = tostring(column_ifexists(\"SrcIp\", \"\")),\n    HttpUserAgent = tostring(column_ifexists(\"HttpUserAgent\", \"\")),\n    ServiceName = tostring(column_ifexists(\"ServiceName\", \"\")),\n    Severity = tostring(column_ifexists(\"Severity\", \"\")),\n    UserUid = tostring(column_ifexists(\"UserUid\", \"\")),\n    ActorUserUid = tostring(column_ifexists(\"ActorUserUid\", \"\"))\n| where ActivityName =~ \"MFA Disabled\"\n| where isnotempty(UserEmail) or isnotempty(ActorUserEmail)\n| extend TargetAccount = iff(isnotempty(UserEmail), UserEmail, ActorUserEmail)\n| project\n    TimeGenerated,\n    TargetAccount,\n    UserEmail,\n    ActorUserEmail,\n    SrcIp,\n    HttpUserAgent,\n    ServiceName,\n    ActivityName,\n    Severity,\n    UserUid,\n    ActorUserUid\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion"
        ],
        "techniques": [
          "T1556"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}