Microsoft Defender for Cloud Apps
Cloud and workloads

How to investigate anomaly detection alerts | Microsoft Defender for Cloud Apps

In brief

The article now uses clearer MITRE ATT&CK tactic terminology, names specific detections, and clarifies learning periods and B-TP examples for anomalous locations and impossible travel alerts.

What Defender admins need to know

Administrators can more easily identify detection types and interpret alert context. No administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How to investigate anomaly detection alerts

MITRE ATT&CK coverage for anomaly detection alerts

To explain and make it easier to map the relationship between Defender for Cloud Apps alerts and the familiar MITRE ATT&CK Matrix, we've categorized the alerts by their corresponding MITRE ATT&CK tactic. This extra referenceMITRE ATT&CK mapping makes it easier to understand the suspected attacksattack technique potentially in use when a Defender for Cloud Apps alert is triggered.

This guide provides information about investigating and remediating Defender for Cloud Apps alerts in the following categories.MITRE ATT&CK tactic categories:

[!div class="checklist"]

TP, B-TP, or FP?

ThisThe anonymous proxy detection uses a machine learning algorithm that reduces B-TP incidents, such as mis-tagged IP addresses that are widely used by users in the organization.

  1. TP: If you're able to confirm that the activity was performed from an anonymous or TOR IP address.

Learning period

The infrequent country detection requires time to learn normal location patterns before it can alert accurately. Detecting anomalous locations requires an initial learning period of seven days during which alerts aren't triggered for any new locations.

TP, B-TP, or FP?

**Recommended action**:
1. Suspend the user, reset their password, and identify the right time to safely re-enable the account.
1. Optional: Create a playbook using Power Automate to contact users detected as connecting from infrequent locations, and their managers, to verify their activity.
  1. B-TP: If a user is known to be at this location.the country or region identified in the alert. For example, when a user who travels frequently and is currently in the specified location.

    Recommended action:

    1. Dismiss the alert and modify the policy to exclude the user.

Learning period

The Impossible travel detection needs an initial observation period to establish normal travel patterns for each user. Establishing a new user's activity pattern requires an initial learning period of seven days during which alerts aren't triggered for any new locations.

TP, B-TP, or FP?

ThisThe Impossible travel detection uses a machine learning algorithm that ignores obvious B-TP conditions, such as when the IP addresses on both sides of the travel are considered safe, the travel is trusted and excluded from triggering the Impossible travel detection. For example, both sides are considered safe if they're tagged as corporate. However, if the IP address of only one side of the travel is considered safe, the detection is triggered as normal.

  1. TP: If you're able to confirm that the location in the impossible travel alert is unlikely for the user.

Misleading OAuth app name

ThisThe misleading OAuth app name detection identifies apps with characters, such as foreign letters, that resemble Latin letters. This can indicate an attempt to disguise a malicious app as a known and trusted app so that attackers can deceive users into downloading their malicious app.

TP, B-TP, or FP?

Misleading publisher name for an OAuth app

ThisThe misleading publisher name detection identifies apps with characters, such as foreign letters, that resemble Latin letters. This can indicate an attempt to disguise a malicious app as a known and trusted app so that attackers can deceive users into downloading their malicious app.

TP, B-TP, or FP?

As part of ongoing improvements to Defender for Cloud Apps alert threat protection capabilities, this policy has been disabled, migrated to the new dynamic model. If you previously configured governance actions or email notifications for this policy, you can re-enable it at any time in the Microsoft Defender portal > Cloud Apps > Policy management page.

Activities indicating that an attacker gained access to a user's inbox and created a suspicious rule. Manipulation rules, such as deleting or moving messages, or folders, from a user's inbox might be an attempt to exfiltrate information from your organization. Similarly, they can indicate an attempt to manipulate information that a user sees or to use their inbox to distribute spam, phishing emails, or malware. Defender for Cloud Apps profiles your environment and triggers alerts when suspicious inbox manipulation rules are detected on a user's inbox. ThisDetecting suspicious inbox manipulation rules might indicate that the user's account is compromised.

TP, B-TP, or FP?

Learning period

The detection requires an initial seven-day learning period to establish a new user's activity pattern. During this time, alerts aren't triggered for any new locations.

TP, B-TP, or FP?

Learning period

The multiple failed login attempts detection needs time to learn each user's normal sign-in behavior before it can alert accurately. Establishing a new user's activity pattern requires an initial learning period of seven days during which alerts aren't triggered for any new locations.

TP, B-TP, or FP?

Learning period

Establishing a new user's activity pattern requires an initial learning period of seven days during which alerts aren't triggered for any new locations.

TP, B-TP, or FP?

ThisThe multiple failed login attempts policy is based on learning the normal sign in behavior of a user. When a deviation from the norm is detected, an alert is triggered. If the detection begins to see that the same behavior continues, the alert is only raised once.

  1. TP (MFA fails): If you're able to confirm that MFA is working correctly, this could be a sign of an attempted brute force attack.

Unusual addition of credentials to an OAuth app

ThisThe unusual addition of credentials detection identifies the suspicious addition of privileged credentials to an OAuth app. This can indicate that an attacker has compromised the app, and is using it for malicious activity.

Learning period

Unusual ISP for an OAuth app

The detection identifies an OAuth app connecting to your cloud application from an ISP that is uncommon for the app. ThisAn OAuth app connecting from an uncommon ISP might indicate that an attacker tried to use a legitimate compromised app to perform malicious activities on your cloud applications.

Learning period

Suspicious Power BI report sharing

Activities indicating that a user shared a Power BI report that might contain sensitive information identified using NLPnatural language processing (NLP) to analyze the metadata of the report. The report was either shared with an external email address, published to the web, or a snapshot was delivered to an externally subscribed email address. This can indicate an attempted breach of your organization.

TP, B-TP, or FP?