e91fc4486e
see discussion here: https://github.com/SigmaHQ/sigma/discussions/2835
34 lines
949 B
YAML
34 lines
949 B
YAML
title: Microsoft 365 Rules
|
|
order: 10
|
|
logsources:
|
|
threat_management:
|
|
product: m365
|
|
service: threat_management
|
|
conditions:
|
|
eventSource: SecurityComplianceCenter
|
|
access_governance:
|
|
product: m365
|
|
service: access_governance
|
|
conditions:
|
|
eventSource: SecurityComplianceCenter
|
|
cloud_discovery:
|
|
product: m365
|
|
service: cloud_discovery
|
|
conditions:
|
|
eventSource: SecurityComplianceCenter
|
|
data_loss_prevention:
|
|
product: m365
|
|
service: data_loss_prevention
|
|
conditions:
|
|
eventSource: SecurityComplianceCenter
|
|
threat_detection:
|
|
product: m365
|
|
service: threat_detection
|
|
conditions:
|
|
eventSource: SecurityComplianceCenter
|
|
sharing_control:
|
|
product: m365
|
|
service: sharing_control
|
|
conditions:
|
|
eventSource: SecurityComplianceCenter
|