Files
blue-team-tools/tools/config/generic/m365.yml
T

34 lines
949 B
YAML
Raw Normal View History

2021-08-20 00:29:29 -05:00
title: Microsoft 365 Rules
order: 10
2021-11-09 07:27:25 +01:00
logsources:
threat_management:
2021-11-09 07:27:25 +01:00
product: m365
service: threat_management
2021-11-09 07:27:25 +01:00
conditions:
eventSource: SecurityComplianceCenter
access_governance:
2021-11-09 07:27:25 +01:00
product: m365
service: access_governance
2021-11-09 07:27:25 +01:00
conditions:
eventSource: SecurityComplianceCenter
cloud_discovery:
2021-11-09 07:27:25 +01:00
product: m365
service: cloud_discovery
2021-11-09 07:27:25 +01:00
conditions:
eventSource: SecurityComplianceCenter
data_loss_prevention:
2021-11-09 07:27:25 +01:00
product: m365
service: data_loss_prevention
2021-11-09 07:27:25 +01:00
conditions:
eventSource: SecurityComplianceCenter
threat_detection:
2021-11-09 07:27:25 +01:00
product: m365
service: threat_detection
2021-11-09 07:27:25 +01:00
conditions:
eventSource: SecurityComplianceCenter
sharing_control:
2021-11-09 07:27:25 +01:00
product: m365
service: sharing_control
2021-11-09 07:27:25 +01:00
conditions:
eventSource: SecurityComplianceCenter