Platform / product
m365 Sigma detection rules
21 community-maintained Sigma detection rules in the library target the m365 platform. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
Azure Login Bypassing Conditional Access Policies
highDetects a successful login to the Microsoft Intune Company Portal which could allow bypassing Conditional Access Policies and InTune device trust using a tool like TokenSmith.
m365 · audit
Disabling Multi Factor Authentication
highDetects disabling of Multi Factor Authentication.
m365 · audit
Activity from Anonymous IP Addresses
mediumDetects when a Microsoft Cloud App Security reported when users were active from an IP address that has been identified as an anonymous proxy IP address.
m365 · threat_management
Activity from Infrequent Country
mediumDetects when a Microsoft Cloud App Security reported when an activity occurs from a location that wasn't recently or never visited by any user in the organization.
m365 · threat_management
Activity from Suspicious IP Addresses
mediumDetects when a Microsoft Cloud App Security reported users were active from an IP address identified as risky by Microsoft Threat Intelligence. These IP addresses are involved in malicious activities, such as Botnet C&C, and may indicate compromised account.
m365 · threat_detection
Activity Performed by Terminated User
mediumDetects when a Microsoft Cloud App Security reported for users whose account were terminated in Azure AD, but still perform activities in other platforms such as AWS or Salesforce. This is especially relevant for users who use another account to manage resources, since these accounts are often not terminated when a user leaves the company.
m365 · threat_management
Data Exfiltration to Unsanctioned Apps
mediumDetects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform an activity that resembles an attempt to exfiltrate information from your organization.
m365 · threat_management
Inbox Rules Creation Or Update Activity in O365
mediumDetects inbox rule creation or update via O365 Audit logs, a technique commonly observed in Business Email Compromise (BEC) attacks to hide emails. The usage of inbox rules can be a sign of a compromised mailbox, where an attacker is attempting to evade detections by suppressing or redirecting incoming emails. Analysts should review these rules in context, validate whether they reflect normal user behavior, and correlate with other indicators such as unusual login activity or recent mailbox rule modifications.
m365 · audit
Logon from a Risky IP Address
mediumDetects when a Microsoft Cloud App Security reported when a user signs into your sanctioned apps from a risky IP address.
m365 · threat_management
Mail Forwarding/Redirecting Activity In O365
mediumDetects email forwarding or redirecting activity in O365 Audit logs.
m365 · audit
Microsoft 365 - Impossible Travel Activity
mediumDetects when a Microsoft Cloud App Security reported a risky sign-in attempt due to a login associated with an impossible travel.
m365 · threat_management
Microsoft 365 - Potential Ransomware Activity
mediumDetects when a Microsoft Cloud App Security reported when a user uploads files to the cloud that might be infected with ransomware.
m365 · threat_management
Microsoft 365 - Unusual Volume of File Deletion
mediumDetects when a Microsoft Cloud App Security reported a user has deleted a unusual a large volume of files.
m365 · threat_management
Microsoft 365 - User Restricted from Sending Email
mediumDetects when a Security Compliance Center reported a user who exceeded sending limits of the service policies and because of this has been restricted from sending email.
m365 · threat_management
New Federated Domain Added
mediumDetects the addition of a new Federated Domain.
m365 · audit
New Federated Domain Added - Exchange
mediumDetects the addition of a new Federated Domain.
m365 · exchange
PST Export Alert Using eDiscovery Alert
mediumAlert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content
m365 · threat_management
PST Export Alert Using New-ComplianceSearchAction
mediumAlert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.
m365 · threat_management
Suspicious Email Delivered In Microsoft 365
mediumDetects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder. It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.
m365 · audit
Suspicious OAuth App File Download Activities
mediumDetects when a Microsoft Cloud App Security reported when an app downloads multiple files from Microsoft SharePoint or Microsoft OneDrive in a manner that is unusual for the user.
m365 · threat_management
Suspicious Inbox Forwarding
lowDetects when a Microsoft Cloud App Security reported suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.
m365 · threat_management