Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleSecOpsDataExfiltrationToUnsanctionedAppsO365

Detects attempts to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).

Source table → cloud.office365.siem_agent_event

Expand
titleSecOpsCloudDiscoveryAnomalyDetectionO365

This policy is automatically enabled to alert you when anomalous behavior is detected in discovered users, IP addresses, and services, such as large amounts of uploaded data compared to other users, and large service transactions compared to the service's history.

Source table → cloud.office365.siem_agent_event