Files
blue-team-tools/tools/config/generic/m365.yml
T
2021-11-09 07:27:25 +01:00

34 lines
937 B
YAML

title: Microsoft 365 Rules
order: 10
logsources:
ThreatManagement:
product: m365
category: ThreatManagement
conditions:
eventSource: SecurityComplianceCenter
AccessGovernance:
product: m365
category: AccessGovernance
conditions:
eventSource: SecurityComplianceCenter
CloudDiscovery:
product: m365
category: CloudDiscovery
conditions:
eventSource: SecurityComplianceCenter
DataLossPrevention:
product: m365
category: DataLossPrevention
conditions:
eventSource: SecurityComplianceCenter
ThreatDetection:
product: m365
category: ThreatDetection
conditions:
eventSource: SecurityComplianceCenter
SharingControl:
product: m365
category: SharingControl
conditions:
eventSource: SecurityComplianceCenter