Web Credential Creation

Initial construction of new web credential material (ex: Windows EID 1200 or 4769)

ID: DC0006
Domains: Enterprise
Version: 2.0
Created: 20 October 2021
Last Modified: 21 October 2025

Log Sources

Name Channel
AWS:CloudTrail AssumeRole, GetFederationToken API calls by unusual or new entities
azure:signinLogs SAML/OIDC tokens issued without corresponding MFA or password validation
m365:oauth OAuth grants or tokens issued without expected user consent
m365:unified Session creation without MFA or login event
WinEventLog:ADFS Token issuance events showing anomalous claims or issuers

Detection Strategy