Skip to content

Commit 5e12f05

Browse files
fixing double header in investigation notes (#4490)
1 parent 3bbe24d commit 5e12f05

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

rules/integrations/azure/credential_access_first_time_seen_device_code_auth.toml

+1-3
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
creation_date = "2024/10/14"
33
integration = ["azure"]
44
maturity = "production"
5-
updated_date = "2025/02/18"
5+
updated_date = "2025/02/21"
66

77
[rule]
88
author = ["Elastic", "Matteo Potito Giorgio"]
@@ -19,8 +19,6 @@ license = "Elastic License v2"
1919
name = "First Occurrence of Entra ID Auth via DeviceCode Protocol"
2020
note = """## Triage and analysis
2121
22-
## Triage and Analysis
23-
2422
### Investigating First Occurrence of Entra ID Auth via DeviceCode Protocol
2523
2624
This rule detects the first instance of a user authenticating via the **DeviceCode** authentication protocol within a **14-day window**. The **DeviceCode** authentication workflow is designed for devices that lack keyboards, such as IoT devices and smart TVs. However, adversaries can abuse this mechanism by phishing users and stealing authentication tokens, leading to unauthorized access.

0 commit comments

Comments
 (0)