Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleSecOpsO365SuspiciousAdminEmailForwarding

This detection is triggered when a user has configured several forwarding rules to the same email address.

Source table → cloud.office365.management

Expand
titleSecOpsActivityAnonymousIPAddressesO365

This policy profiles your environment and triggers alerts when it identifies activity from an IP address that has been identified as an anonymous proxy IP address. These proxies are used by people who want to hide their device’s IP address and may be used for malicious intent.

Source table → cloud.office365.siem_agent_alert