Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleSecOpsActivityAnonymousIPAddressesO365

This policy profiles your environment and triggers alerts when it identifies activity from an IP address that has been identified as an anonymous proxy IP address. These proxies are used by people who want to hide their device’s IP address and may be used for malicious intent.

Source table → cloud.office365.siem_agent_alert

Expand
titleSecOpsGroupMembershipModifiedO365

Group Membership Modified.

Source table → cloud.office365.siem_agent_event

Expand
titleSecOpsDataExfiltrationToUnsanctionedAppsO365

Detects attempts to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).

Source table → cloud.office365.siem_agent_event