Files
blue-team-tools/tools/config/generic/m365.yml
T

34 lines
949 B
YAML

title: Microsoft 365 Rules
order: 10
logsources:
threat_management:
product: m365
service: threat_management
conditions:
eventSource: SecurityComplianceCenter
access_governance:
product: m365
service: access_governance
conditions:
eventSource: SecurityComplianceCenter
cloud_discovery:
product: m365
service: cloud_discovery
conditions:
eventSource: SecurityComplianceCenter
data_loss_prevention:
product: m365
service: data_loss_prevention
conditions:
eventSource: SecurityComplianceCenter
threat_detection:
product: m365
service: threat_detection
conditions:
eventSource: SecurityComplianceCenter
sharing_control:
product: m365
service: sharing_control
conditions:
eventSource: SecurityComplianceCenter