-
Deprecated - M365 Exchange DLP Policy Deleted
Identifies when a Data Loss Prevention (DLP) policy is removed in Microsoft 365. An adversary may remove a DLP policy to evade existing DLP monitoring.
Read More -
Identifies when Microsoft Cloud App Security flags potential ransomware activity in Microsoft 365. This rule detects events where the Security Compliance Center reports a "Ransomware activity" or "Potential ransomware activity" alert, which may indicate file encryption, mass file modifications, or uploads of ransomware-infected files to cloud services such as SharePoint or OneDrive.
Read More -
Identifies that a user has deleted an unusually large volume of files as reported by Microsoft Cloud App Security.
Read More -
Identifies when a user has been restricted from sending email due to exceeding sending limits of the service policies per the Security Compliance Center.
Read More -
Identifies when external access is enabled in Microsoft Teams. External access lets Teams and Skype for Business users communicate with other users that are outside their organization. An adversary may enable external access or add an allowed domain to exfiltrate data or maintain persistence in an environment.
Read More -
Identifies when guest access is enabled in Microsoft Teams. Guest access in Teams allows people outside the organization to access teams and channels. An adversary may enable guest access to maintain persistence in an environment.
Read More -
Entra ID Kali365 Default User-Agent Detected
Sep 19, 2026 · Domain: Cloud Domain: Identity Data Source: Azure Data Source: Microsoft Entra ID Data Source: Microsoft Entra ID Sign-In Logs Data Source: Microsoft Entra ID Audit Logs Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Use Case: Threat Detection Threat: Kali365 Tactic: Initial Access Tactic: Credential Access Resources: Investigation Guide Noise: Unknown Performance: Normal Profile: Recommended Threat: AiTM Phishing Rule Type: Custom Query (KQL) Platform: Entra ID Platform: Microsoft 365 Domain: SaaS Domain: Email ·Identifies the default user agent string associated with Kali365 (also referred to as Kali365 Live), a phishing-as-a-service (PhaaS) platform that automates OAuth 2.0 device code phishing and adversary-in-the-middle (AiTM) session capture against Microsoft 365 and Microsoft Entra ID. The Kali365 Electron desktop client identifies itself with the user agent
kali365-live/1.0.0when polling for and replaying captured OAuth tokens, so its appearance in Entra ID sign-in logs, Entra ID audit logs, or the Microsoft 365 unified audit log indicates that an attacker-controlled Kali365 client is interacting with the tenant using stolen tokens. Unlike dual-use offensive tooling, Kali365 is a criminal service with no legitimate enterprise use, making this user agent a high-fidelity indicator of active account compromise.
Read More -
Entra ID Sign-in BloodHound Suite User-Agent Detected
Sep 19, 2026 · Domain: Cloud Data Source: Azure Data Source: Azure Activity Logs Data Source: Graph API Data Source: Graph API Activity Logs Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Data Source: Microsoft Entra ID Data Source: Microsoft Entra ID Audit Logs Data Source: Microsoft Entra ID Sign-In Logs Use Case: Identity and Access Audit Use Case: Threat Detection Tactic: Discovery Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Event Correlation (EQL) Platform: Entra ID Domain: Identity Platform: Microsoft 365 Domain: SaaS ·Identifies potential enumeration activity using AzureHound, SharpHound, or BloodHound across Microsoft cloud services. These tools are often used by red teamers and adversaries to map users, groups, roles, applications, and access relationships within Microsoft Entra ID (Azure AD) and Microsoft 365.
Read More -
Entra ID Sign-in TeamFiltration User-Agent Detected
Sep 19, 2026 · Domain: Cloud Data Source: Azure Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Data Source: Microsoft Entra ID Data Source: Microsoft Entra ID Sign-In Logs Use Case: Identity and Access Audit Use Case: Threat Detection Tactic: Discovery Resources: Investigation Guide Noise: Low Performance: Fast Profile: Recommended Rule Type: Custom Query (KQL) Platform: Entra ID Domain: Identity Platform: Microsoft 365 Domain: SaaS ·Identifies potential enumeration or password spraying activity using TeamFiltration tool. TeamFiltration is an open-source enumeration, password spraying and exfiltration tool designed for Entra ID and Microsoft 365. Adversaries are known to use TeamFiltration in-the-wild to enumerate users, groups, and roles, as well as to perform password spraying attacks against Microsoft Entra ID and Microsoft 365 accounts. This rule detects the use of TeamFiltration by monitoring for specific user-agent strings associated with the tool in Azure and Microsoft 365 logs.
Read More -
M365 Azure Monitor Alert Email with Financial or Billing Theme
Sep 19, 2026 · Domain: Cloud Domain: Email Data Source: Microsoft 365 Data Source: Microsoft Exchange Online Message Trace Use Case: Threat Detection Tactic: Initial Access Resources: Investigation Guide Noise: Unknown Performance: Normal Rule Type: ES|QL Platform: Microsoft 365 Domain: SaaS Service: Microsoft Exchange Online Data Source: Microsoft Exchange Online Logs ·Detects Azure Monitor alert notification emails with financial or billing themed subject lines delivered to organization users. Adversaries abuse Azure Monitor alert rules to deliver callback phishing emails from Microsoft's legitimate azure-noreply@microsoft.com address. Because the emails originate from Microsoft's own infrastructure, they pass SPF, DKIM, and DMARC checks, bypassing email security filters and increasing victim trust. The attacker embeds a fraudulent billing or security lure in the alert rule description, which is rendered in the notification email body. Observed subject patterns include invoice numbers, payment references, and order confirmations.
Read More -
M365 Exchange Anti-Phish Policy Deleted
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Configuration Audit Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies the deletion of an anti-phishing policy in Microsoft 365. By default, Microsoft 365 includes built-in features that help protect users from phishing attacks. Anti-phishing polices increase this protection by refining settings to better detect and prevent attacks.
Read More -
M365 Exchange Anti-Phish Rule Modification
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Configuration Audit Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies the modification of an anti-phishing rule in Microsoft 365. By default, Microsoft 365 includes built-in features that help protect users from phishing attacks. Anti-phishing rules increase this protection by refining settings to better detect and prevent attacks.
Read More -
M365 Exchange DKIM Signing Configuration Disabled
Identifies when a DomainKeys Identified Mail (DKIM) signing configuration is disabled in Microsoft 365. With DKIM in Microsoft 365, messages that are sent from Exchange Online will be cryptographically signed. This will allow the receiving email system to validate that the messages were generated by a server that the organization authorized and were not spoofed.
Read More -
M365 Exchange Email Safe Attachment Rule Disabled
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Configuration Audit Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies when a safe attachment rule is disabled in Microsoft 365. Safe attachment rules can extend malware protections to include routing all messages and attachments without a known malware signature to a special hypervisor environment. An adversary or insider threat may disable a safe attachment rule to exfiltrate data or evade defenses.
Read More -
M365 Exchange Email Safe Link Policy Disabled
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Identity and Access Audit Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies when a Safe Link policy is disabled in Microsoft 365. Safe Link policies for Office applications extend phishing protection to documents that contain hyperlinks, even after they have been delivered to a user.
Read More -
M365 Exchange Federated Domain Created or Modified
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Identity and Access Audit Tactic: Privilege Escalation Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies a new or modified federation domain, which can be used to create a trust between O365 and an external identity provider.
Read More -
M365 Exchange Inbox Forwarding Rule Created
Sep 19, 2026 · Domain: Cloud Domain: SaaS Domain: Email Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Configuration Audit Tactic: Collection Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: Event Correlation (EQL) Platform: Microsoft 365 Service: Microsoft Exchange Online ·Identifies when a new Inbox forwarding rule is created in Microsoft 365. Inbox rules process messages in the Inbox based on conditions and take actions. In this case, the rules will forward the emails to a defined address. Attackers can abuse Inbox Rules to intercept and exfiltrate email data without making organization-wide configuration changes or having the corresponding privileges.
Read More -
M365 Exchange Inbox Phishing Evasion Rule Created
Sep 19, 2026 · Domain: Cloud Domain: SaaS Domain: Email Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Profile: Recommended Threat: AiTM Phishing Rule Type: New Terms Platform: Microsoft 365 Service: Microsoft Exchange Online ·Identifies when a user creates a new inbox rule in Microsoft 365 that deletes or moves emails containing suspicious keywords. Adversaries who have compromised accounts often create inbox rules to hide alerts, security notifications, or other sensitive messages by automatically deleting them or moving them to obscure folders. Common destinations include Deleted Items, Junk Email, RSS Feeds, and RSS Subscriptions. This is a New Terms rule that triggers only when the user principal name and associated source IP address have not been observed performing this activity in the past 14 days.
Read More -
M365 Exchange Inbox Rule with Obfuscated Name
Sep 19, 2026 · Domain: Cloud Domain: SaaS Domain: Email Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Defense Evasion Resources: Investigation Guide Noise: Unknown Performance: Normal Rule Type: ES|QL Platform: Microsoft 365 Service: Microsoft Exchange Online ·Identifies when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters. Adversaries may use obfuscated inbox rule names to evade detection, hide malicious forwarding or deletion rules, or blend in with benign audit noise. The rule name is parsed from "o365.audit.ObjectId", which encodes the mailbox identity and rule name separated by a backslash.
Read More -
M365 Exchange Mail Flow Transport Rule Created
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Configuration Audit Tactic: Exfiltration Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies a transport rule creation in Microsoft 365. As a best practice, Exchange Online mail transport rules should not be set to forward email to domains outside of your organization. An adversary may create transport rules to exfiltrate data.
Read More -
M365 Exchange Mail Flow Transport Rule Modified
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Configuration Audit Tactic: Exfiltration Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies when a transport rule has been disabled or deleted in Microsoft 365. Mail flow rules (also known as transport rules) are used to identify and take action on messages that flow through your organization. An adversary or insider threat may modify a transport rule to exfiltrate data or evade defenses.
Read More -
M365 Exchange Mailbox Accessed by Unusual Client
Sep 19, 2026 · Domain: Cloud Domain: Email Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Collection Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: New Terms Platform: Microsoft 365 Domain: SaaS Service: Microsoft Exchange Online ·Identifies suspicious Microsoft 365 mail access by ClientAppId. This rule detects when a user accesses their mailbox using a client application that is not typically used by the user, which may indicate potential compromise or unauthorized access attempts. Adversaries may use custom or third-party applications to access mailboxes, bypassing standard security controls. First-party Microsoft applications are also abused after OAuth tokens are compromised, allowing adversaries to access mailboxes without raising suspicion.
Read More -
M365 Exchange Mailbox Audit Logging Bypass Added
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Tactic: Initial Access Tactic: Defense Evasion Resources: Investigation Guide Noise: Medium Performance: Fast Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Detects the occurrence of mailbox audit bypass associations. The mailbox audit is responsible for logging specified mailbox events (like accessing a folder or a message or permanently deleting a message). However, actions taken by some authorized accounts, such as accounts used by third-party tools or accounts used for lawful monitoring, can create a large number of mailbox audit log entries and may not be of interest to your organization. Because of this, administrators can create bypass associations, allowing certain accounts to perform their tasks without being logged. Attackers can abuse this allowlist mechanism to conceal actions taken, as the mailbox audit will log no activity done by the account.
Read More -
M365 Exchange Mailbox High-Risk Permission Delegated
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft Exchange Data Source: Microsoft 365 Audit Logs Use Case: Configuration Audit Tactic: Persistence Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: New Terms Platform: Microsoft 365 Domain: Email Service: Microsoft Exchange Online ·Identifies the assignment of rights to access content from another mailbox. An adversary may use the compromised account to send messages to other accounts in the network of the target organization while creating inbox rules, so messages can evade spam/phishing detection mechanisms.
Read More -
M365 Exchange Mailbox Items Accessed Excessively
Sep 19, 2026 · Domain: Cloud Domain: Email Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Collection Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Service: Microsoft Exchange Online ·Identifies an excessive number of Microsoft 365 mailbox items accessed by a user either via aggregated counts or throttling. Microsoft audits mailbox access via the MailItemsAccessed event, which is triggered when a user accesses mailbox items. If more than 1000 mailbox items are accessed within a 24-hour period, it is then throttled. Excessive mailbox access may indicate an adversary attempting to exfiltrate sensitive information or perform reconnaissance on a target's mailbox. This rule detects both the throttled and unthrottled events with a high threshold.
Read More -
M365 Exchange Malware Filter Policy Deleted
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Configuration Audit Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies when a malware filter policy has been deleted in Microsoft 365. A malware filter policy is used to alert administrators that an internal user sent a message that contained malware. This may indicate an account or machine compromise that would need to be investigated. Deletion of a malware filter policy may be done to evade detection.
Read More -
M365 Exchange Malware Filter Rule Modified
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Configuration Audit Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies when a malware filter rule has been deleted or disabled in Microsoft 365. An adversary or insider threat may want to modify a malware filter rule to evade detection.
Read More -
M365 Exchange Management Group Role Assigned
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Identity and Access Audit Tactic: Persistence Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Domain: Email Data Source: Microsoft 365 Audit Logs Service: Microsoft Exchange Online ·Identifies when a new role is assigned to a management group in Microsoft 365. An adversary may attempt to add a role in order to maintain persistence in an environment.
Read More -
M365 Exchange MFA Notification Email Deleted or Moved
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Defense Evasion Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: Event Correlation (EQL) Platform: Microsoft 365 Domain: Email Service: Microsoft Exchange Online ·Identifies when an MFA enrollment, registration, or security notification email is deleted or moved to deleted items in Microsoft 365 Exchange. Adversaries who compromise accounts and register their own MFA device often delete the notification emails to cover their tracks and prevent the legitimate user from noticing the unauthorized change. This technique is commonly observed in business email compromise (BEC) and account takeover attacks.
Read More -
M365 Identity Device Code Grant by an Unusual User (Non-Compliant Device)
Sep 19, 2026 · Domain: Cloud Domain: SaaS Domain: Identity Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Use Case: Threat Detection Resources: Investigation Guide Tactic: Initial Access Noise: Medium Performance: Normal Profile: Recommended Threat: Device Code Phishing Rule Type: New Terms Platform: Microsoft 365 Domain: Email ·Identifies a Microsoft 365 user completing an OAuth device code grant ("Cmsi:Cmsi") from a non-compliant device for the first time within the rule's historical window, regardless of the requesting application or target resource. Device code phishing kits complete the full login (password and MFA) at the genuine Microsoft endpoint and harvest the resulting token by polling, so MFA does not stop them. Because the victim authorizes the flow in their own browser, the grant is frequently completed on a personal or attacker-controlled device that is not enrolled or compliant with the organization's device policies. A user appearing with this device code flow on a non-compliant device for the first time in the lookback window is a strong early indicator of device code phishing, and removing the application and target constraints catches grants against any first-party application, not just the Microsoft Authentication Broker.
Read More -
M365 Identity Device Code Grant with Unusual User and ASN
Sep 19, 2026 · Domain: Cloud Domain: SaaS Domain: Identity Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Use Case: Threat Detection Resources: Investigation Guide Tactic: Initial Access Noise: Low Performance: Normal Profile: Recommended Threat: Device Code Phishing Rule Type: New Terms Platform: Microsoft 365 Domain: Email ·Identifies a Microsoft 365 OAuth device code grant ("Cmsi:Cmsi") with application Microsoft Authentication Broker ("29d9ed98-a469-4536-ade2-f981bc1d605e") for Microsoft Graph from a source ASN not previously observed for that user in a historical window. Phishing kits leveraging device code phishing complete the full login (password and MFA) at the genuine Microsoft endpoint and harvest the resulting token by polling, so MFA does not stop them and the authorization commonly originates from attacker-controlled residential proxy or hosting infrastructure rather than the user's normal network.
Read More -
M365 Identity Global Administrator Role Assigned
Identifies when the Microsoft 365 Global Administrator or Company Administrator role is assigned to a user or service principal. The Global Administrator role has extensive privileges across Entra ID and Microsoft 365 services, making it a high-value target for adversaries seeking persistent access. Successful assignments of this role may indicate potential privilege escalation or unauthorized access attempts, especially if performed by accounts that do not typically manage high-privilege roles.
Read More -
M365 Identity Login from Atypical Region
Sep 19, 2026 · Domain: Cloud Domain: Identity Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Use Case: Identity and Access Audit Tactic: Initial Access Resources: Investigation Guide Noise: Medium Performance: Normal Profile: Recommended Threat: Impossible Travel Rule Type: New Terms Platform: Microsoft 365 Domain: SaaS ·Detects successful Microsoft 365 portal logins from a country and region the user has not previously authenticated from in a specific time window. Atypical regions are identified by combining the user's country and region geolocation history; an authentication from a new country/region pair for that user may indicate an adversary attempting to access the account from an unusual location or behind a VPN.
Read More -
M365 Identity Login from Impossible Travel Location
Sep 19, 2026 · Domain: Cloud Domain: Identity Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Use Case: Identity and Access Audit Tactic: Initial Access Resources: Investigation Guide Noise: Medium Performance: Normal Profile: Recommended Threat: Impossible Travel Rule Type: Threshold Platform: Microsoft 365 Domain: SaaS ·Detects successful Microsoft 365 portal logins from impossible travel locations. Impossible travel locations are defined as two different countries within a short time frame. This behavior may indicate an adversary attempting to access a Microsoft 365 account from a compromised account or a malicious actor attempting to access a Microsoft 365 account from a different location.
Read More -
M365 Identity OAuth Flow by First-Party Microsoft App from Multiple IPs
Sep 19, 2026 · Domain: Cloud Domain: Email Domain: Identity Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Use Case: Threat Detection Resources: Investigation Guide Tactic: Defense Evasion Noise: Low Performance: Normal Rule Type: ES|QL Platform: Microsoft 365 Domain: SaaS ·Identifies sign-ins on behalf of a principal user to the Microsoft Graph or legacy Azure AD API from multiple IPs using first-party Microsoft applications from the FOCI (Family of Client IDs) group. Developer tools like Azure CLI, VSCode, and Azure PowerShell accessing these resources from multiple IPs are flagged, along with any FOCI application accessing the deprecated Windows Azure Active Directory from multiple IPs. This behavior may indicate an adversary using a phished OAuth authorization code or refresh token, as seen in attacks like ConsentFix where attackers steal localhost OAuth codes and replay them from attacker infrastructure.
Read More -
M365 Identity OAuth Flow by User Sign-in to Device Registration
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Tactic: Credential Access Resources: Investigation Guide Noise: Medium Performance: Normal Profile: Recommended Threat: Device Code Phishing Rule Type: Event Correlation (EQL) Platform: Microsoft 365 Domain: Email ·Identifies attempts to register a new device in Microsoft Entra ID after OAuth authentication with authorization code grant. Adversaries may use OAuth phishing techniques to obtain an OAuth authorization code, which can then be exchanged for access and refresh tokens. This rule detects a sequence of events where a user principal authenticates via OAuth, followed by a device registration event, indicating potential misuse of the OAuth flow to establish persistence or access resources.
Read More -
M365 Identity OAuth Illicit Consent Grant by Rare Client and User
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Resources: Investigation Guide Tactic: Initial Access Tactic: Credential Access Noise: Medium Performance: Normal Profile: Recommended Threat: OAuth App Consent Rule Type: New Terms Platform: Microsoft 365 Domain: SaaS Domain: Email ·Identifies an Microsoft 365 illicit consent grant request on-behalf-of a registered Entra ID application. Adversaries may create and register an application in Microsoft Entra ID for the purpose of requesting user consent to access resources in Microsoft 365. This is accomplished by tricking a user into granting consent to the application, typically via a pre-made phishing URL. This establishes an OAuth grant that allows the malicious client applocation to access resources in Microsoft 365 on-behalf-of the user.
Read More -
M365 Identity OAuth Phishing via First-Party Microsoft Application
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Resources: Investigation Guide Tactic: Initial Access Noise: Low Performance: Normal Profile: Recommended Threat: AiTM Phishing Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: Email ·Detects potentially suspicious OAuth authorization activity in Microsoft 365 where first-party Microsoft applications from the FOCI (Family of Client IDs) group request access to Microsoft Graph or legacy Azure AD resources. Developer tools like Azure CLI, Visual Studio Code, and Azure PowerShell accessing these resources are flagged, as they are commonly abused in phishing campaigns like ConsentFix. Additionally, any FOCI family application accessing the deprecated Windows Azure Active Directory resource is flagged since this API is rarely used legitimately and attackers target it for stealth. First-party apps are trusted by default in all tenants and cannot be blocked, making them ideal for OAuth phishing attacks.
Read More -
M365 Identity OAuth ROPC Grant via Legacy Authentication Client
Sep 19, 2026 · Domain: Cloud Domain: Identity Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Tactic: Initial Access Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: New Terms Platform: Microsoft 365 Domain: SaaS Domain: Email ·Identifies a successful login by a user principal through a legacy authenticated client (such as Authenticated SMTP, IMAP, POP, or Exchange ActiveSync) in the Microsoft 365 Unified Audit Log, evidenced by the "BAV2ROPC" user agent. Legacy basic-authentication clients are translated by Entra ID into a Resource Owner Password Credentials (ROPC) grant, a single-factor flow that submits the user's password directly and bypasses interactive multi-factor authentication. This is commonly abused during password spraying and account takeover.
Read More -
M365 Identity Unusual SSO Authentication Errors for User
Sep 19, 2026 · Domain: Identity Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Use Case: Threat Detection Tactic: Initial Access Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: New Terms Platform: Microsoft 365 Domain: SaaS Domain: Cloud Domain: Email ·Identifies the first occurrence of SSO, SAML, or federated authentication errors for a user. These errors may indicate token manipulation, SAML assertion tampering, or OAuth phishing attempts. Modern adversaries often target SSO mechanisms through token theft, SAML response manipulation, or exploiting federated authentication weaknesses rather than traditional brute force attacks.
Read More -
M365 Identity User Account Lockouts
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Use Case: Identity and Access Audit Tactic: Credential Access Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Rule Type: ES|QL Platform: Microsoft 365 ·Detects a burst of Microsoft 365 user account lockouts within a short 5-minute window. A high number of IdsLocked login errors across multiple user accounts may indicate brute-force attempts for the same users resulting in lockouts.
Read More -
M365 Identity User Brute Force Attempted
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Use Case: Threat Detection Tactic: Credential Access Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Threat: Brute Force Rule Type: ES|QL Platform: Microsoft 365 ·Identifies brute-force authentication activity targeting Microsoft 365 user accounts using failed sign-in patterns that match password spraying, credential stuffing, or password guessing behavior. Adversaries may attempt brute-force authentication with credentials obtained from previous breaches, leaks, marketplaces or guessable passwords.
Read More -
Identifies the occurrence of files uploaded to OneDrive being detected as Malware by the file scanning engine. Attackers can use File Sharing and Organization Repositories to spread laterally within the company and amplify their access. Users can inadvertently share these files without knowing their maliciousness, giving adversaries an opportunity to gain initial access to other endpoints in the environment.
Read More -
M365 OneDrive/SharePoint Excessive File Downloads
Sep 19, 2026 · Domain: Cloud Domain: SaaS Domain: Storage Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Data Source: SharePoint Data Source: OneDrive Use Case: Threat Detection Tactic: Collection Tactic: Exfiltration Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: ES|QL Platform: Microsoft 365 Domain: Email Service: Microsoft SharePoint Service: Microsoft OneDrive ·Identifies when an excessive number of files are downloaded from OneDrive or SharePoint by an authorized user or application in a short period of time. This may indicate a potential data exfiltration event, especially if the downloads are performed using OAuth authentication which could suggest an OAuth phishing attack such as Device Code Authentication phishing.
Read More -
M365 or Entra ID Identity Sign-in from a Suspicious Source
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Azure Data Source: Entra ID Data Source: Entra ID Sign-In Logs Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Use Case: Threat Detection Tactic: Initial Access Resources: Investigation Guide Rule Type: Higher-Order Rule Noise: Medium Performance: Normal Rule Type: ES|QL Platform: Entra ID Domain: Identity Platform: Microsoft 365 Domain: Email ·This rule correlate Entra-ID or Microsoft 365 mail successful sign-in events with network security alerts by source address. Adversaries may trigger some network security alerts such as reputation or other anomalies before accessing cloud resources.
Read More -
M365 Potential AiTM UserLoggedIn via Office App (Tycoon2FA)
Sep 19, 2026 · Domain: Cloud Domain: Identity Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Threat: Tycoon2FA Tactic: Initial Access Tactic: Credential Access Resources: Investigation Guide Noise: Unknown Performance: Normal Profile: Recommended Threat: AiTM Phishing Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: Email ·Detects Microsoft 365 audit "UserLoggedIn" events consistent with Tycoon 2FA phishing-as-a-service (PhaaS) adversary-in-the-middle (AiTM) activity: the Microsoft Authentication Broker requesting access where the object identifier matches Microsoft Graph or Exchange Online, or the Office web client application authenticating to itself, combined with Node.js-style user agents (node, axios, undici). Tycoon 2FA bypasses MFA by relaying authentication and capturing session material, often targeting Microsoft 365 and Gmail. Baseline legitimate automation and developer tooling before tuning.
Read More -
Identifies the occurrence of files uploaded to SharePoint being detected as Malware by the file scanning engine. Attackers can use File Sharing and Organization Repositories to spread laterally within the company and amplify their access. Users can inadvertently share these files without knowing their maliciousness, giving adversaries opportunities to gain initial access to other endpoints in the environment.
Read More -
M365 SharePoint Search for Sensitive Content
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Discovery Tactic: Collection Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: Event Correlation (EQL) Platform: Microsoft 365 Service: Microsoft SharePoint ·Identifies search queries in SharePoint containing sensitive terms related to credentials, financial data, PII, legal matters, or infrastructure information. Adversaries who compromise user accounts often search for high-value files before exfiltration. This rule detects searches containing terms across multiple sensitivity categories, regardless of the access method (browser, PowerShell, or API). The actual search query text is analyzed against a curated list of sensitive terms to identify potential reconnaissance activity.
Read More -
M365 SharePoint Site Administrator Added
Sep 19, 2026 · Domain: Cloud Domain: SaaS Domain: Identity Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Identity and Access Audit Tactic: Privilege Escalation Tactic: Persistence Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Service: Microsoft SharePoint ·Identifies when a new SharePoint Site Administrator is added in Microsoft 365. Site Administrators have full control over SharePoint Sites, including the ability to manage permissions, access all content, and modify site settings. Adversaries who compromise a privileged account may add themselves or a controlled account as a Site Administrator to maintain persistent, high-privilege access to sensitive SharePoint data. This technique was notably observed in the 0mega ransomware campaign, where attackers elevated privileges to exfiltrate data and deploy ransom notes across SharePoint sites.
Read More -
M365 SharePoint Site Sharing Policy Weakened
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Defense Evasion Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Service: Microsoft SharePoint ·Identifies when a SharePoint or OneDrive site sharing policy is changed to weaken security controls. The SharingPolicyChanged event fires for many routine policy modifications, but this rule targets specific high-risk transitions where sharing restrictions are relaxed. This includes enabling guest sharing, enabling anonymous link sharing, making a site public, or enabling guest user access. Adversaries who compromise administrative accounts may weaken sharing policies to exfiltrate data to external accounts or create persistent external access paths.
Read More -
M365 SharePoint/OneDrive File Access via PowerShell
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Collection Tactic: Exfiltration Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: New Terms Platform: Microsoft 365 Domain: Email Service: Microsoft SharePoint Service: Microsoft OneDrive ·Identifies file downloads or access from OneDrive or SharePoint using PowerShell-based user agents. Adversaries may use native PowerShell cmdlets like Invoke-WebRequest or Invoke-RestMethod with Microsoft Graph API to exfiltrate data after compromising OAuth tokens via device code phishing or other credential theft techniques. This rule detects both direct PowerShell access and PnP PowerShell module usage for file operations. FileAccessed events are included to detect adversaries reading file content via API and saving locally, bypassing traditional download methods. Normal users access SharePoint/OneDrive via browsers or sync clients, making PowerShell-based file access inherently suspicious.
Read More -
M365 Teams Custom Application Interaction Enabled
Sep 19, 2026 · Domain: Cloud Data Source: Microsoft 365 Use Case: Configuration Audit Tactic: Defense Evasion Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: SaaS Data Source: Microsoft 365 Audit Logs Service: Microsoft Teams ·Identifies when custom applications are allowed in Microsoft Teams. If an organization requires applications other than those available in the Teams app store, custom applications can be developed as packages and uploaded. An adversary may abuse this behavior to establish persistence in an environment.
Read More -
M365 Teams Rogue Help Desk Chat Created
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Initial Access Resources: Investigation Guide Noise: Low Performance: Normal Rule Type: Custom Query (KQL) Platform: Microsoft 365 Domain: Email Service: Microsoft Teams ·Identifies a one-on-one Microsoft Teams chat created by a user from a foreign tenant whose display name, member profile, or email local-part resembles IT help desk or Microsoft security staff. Adversaries abuse cross-tenant Teams external access to impersonate support personnel and socially engineer victims into granting remote access or disclosing credentials.
Read More