[Rule Tuning] M365 SharePoint/OneDrive File Access via PowerShell - Convert to new_terms (#5873)

Fixes #5872
This commit is contained in:
Terrance DeJesus
2026-03-26 11:28:36 -04:00
committed by GitHub
parent 5d5e1d9ca4
commit 18a28762bf
@@ -2,7 +2,7 @@
creation_date = "2026/02/24"
integration = ["o365"]
maturity = "production"
updated_date = "2026/02/24"
updated_date = "2026/03/23"
[rule]
author = ["Elastic"]
@@ -73,7 +73,7 @@ tags = [
"Resources: Investigation Guide",
]
timestamp_override = "event.ingested"
type = "query"
type = "new_terms"
query = '''
event.dataset: "o365.audit" and
@@ -114,3 +114,25 @@ id = "TA0010"
name = "Exfiltration"
reference = "https://attack.mitre.org/tactics/TA0010/"
[rule.investigation_fields]
field_names = [
"@timestamp",
"user.id",
"user_agent.original",
"event.action",
"event.provider",
"source.ip",
"source.geo.country_name",
"o365.audit.ApplicationId",
"o365.audit.SiteUrl",
"file.name",
"file.directory",
]
[rule.new_terms]
field = "new_terms_fields"
value = ["user.id", "user_agent.original"]
[[rule.new_terms.history_window_start]]
field = "history_window_start"
value = "now-7d"