From af3fd2fe8ecddef6f5cffa7f6ae479bd18a1d54e Mon Sep 17 00:00:00 2001 From: Austin Songer Date: Tue, 6 Jul 2021 16:55:54 -0500 Subject: [PATCH] Create microsoft365_impossible_travel_activity.yml --- ...icrosoft365_impossible_travel_activity.yml | 26 +++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 rules/cloud/microsoft365_impossible_travel_activity.yml diff --git a/rules/cloud/microsoft365_impossible_travel_activity.yml b/rules/cloud/microsoft365_impossible_travel_activity.yml new file mode 100644 index 000000000..9ace49e27 --- /dev/null +++ b/rules/cloud/microsoft365_impossible_travel_activity.yml @@ -0,0 +1,26 @@ +title: Microsoft 365 - Impossible Travel Activity +id: d7eab125-5f94-43df-8710-795b80fa1189 +status: experimental +description: Detects when a Microsoft Cloud App Security reported a risky sign-in attempt due to a login associated with an impossible travel. +author: austinsonger +date: 2020/07/06 +modified: 2020/07/06 +references: + - https://docs.microsoft.com/en-us/cloud-app-security/anomaly-detection-policy + - https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference +logsource: + service: Office365 +detection: + selection: + eventSource: SecurityComplianceCenter + eventName: "Impossible travel activity" + status: success + condition: selection +falsepositives: + - +level: medium +tags: + - attack.initial_access + - attack.t1078 + +