Failed sign-ins into LastPass due to MFA

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This rule will check if a sign-in failed into LastPass due to MFA. An incident can indicate the potential brute forcing of a LastPass account. The use of MFA is identified by combining the sign-in logs, this rule assumes LastPass is federated to Entra ID.

Attribute Value
Type Analytic Rule
Solution Lastpass Enterprise Activity Monitoring
ID 760b8467-e6cc-4006-9149-5696845c1a54
Severity Low
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1078, T1190
Required Connectors LastPass, AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
LastPassNativePoller_CL 🔶 ? ?
SigninLogs ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Lastpass Enterprise Activity Monitoring