Could legitimate cloud activity look suspicious?¶
Yes. Security alerts identify behaviour that met a provider rule or differed from a baseline; they do not by themselves establish malicious activity. Travel, remote work, mobile routing, VPNs, software updates, automation and organisational change can all create unusual-looking events.
Examine the events beneath the alert¶
Preserve the alert, its rule or reason, and the underlying authentication, session, token, application and audit records. A risk label may summarise several signals while omitting fields needed to test them.
Compare the account, device, application, connection, authentication method and later actions with approved travel, work duties, system migrations and administrator changes. Baselines may be unreliable after mergers or new working practices.
Test explanations against the whole sequence¶
A genuine trip may explain a location estimate but not an unexpected privilege change. An approved bulk download may fit a role but still leave unexplained application consent or forwarding rules. Conversely, several individually unusual events may share one legitimate technical cause.
Do not dismiss an alert because one benign explanation is available, and do not label the activity hostile merely because it is unusual. State which parts of the sequence each explanation accounts for, what contradicts it and what corroboration remains necessary.
The point to remember
Suspicious-looking cloud activity is a lead. Test benign and malicious explanations against the underlying records and the complete sequence, not the alert label alone.