[Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4648)

(cherry picked from commit b429be2bda)
This commit is contained in:
Isai
2025-04-24 00:49:06 -04:00
committed by tradebot-elastic
parent 48e9b20967
commit 0e3e5ed269
@@ -2,7 +2,7 @@
creation_date = "2021/05/17"
integration = ["o365"]
maturity = "production"
updated_date = "2025/04/01"
updated_date = "2025/04/23"
[rule]
author = ["Elastic", "Austin Songer"]
@@ -63,8 +63,8 @@ type = "query"
query = '''
event.dataset:o365.audit and event.provider:Exchange and event.action:Add-MailboxPermission and
o365.audit.Parameters.AccessRights:(FullAccess or SendAs or SendOnBehalf) and event.outcome:success and
not user.id : "NT AUTHORITY\SYSTEM (Microsoft.Exchange.ServiceHost)"
o365.audit.Parameters.AccessRights:(FullAccess or SendAs or SendOnBehalf) and event.outcome:success
and not user.id:("NT AUTHORITY\SYSTEM (Microsoft.Exchange.ServiceHost)" or "NT AUTHORITY\SYSTEM (Microsoft.Exchange.AdminApi.NetCore)" or "NT AUTHORITY\SYSTEM (w3wp)")
'''
@@ -86,3 +86,15 @@ id = "TA0003"
name = "Persistence"
reference = "https://attack.mitre.org/tactics/TA0003/"
[rule.investigation_fields]
field_names = [
"@timestamp",
"o365.audit.ObjectId",
"user.id",
"o365.audit.Parameters.User",
"o365.audit.Parameters.AccessRights",
"source.ip",
"user_agent.original",
"event.action",
]