diff --git a/rules/integrations/o365/persistence_exchange_suspicious_mailbox_right_delegation.toml b/rules/integrations/o365/persistence_exchange_suspicious_mailbox_right_delegation.toml index e4563d0d5..2d53fa49a 100644 --- a/rules/integrations/o365/persistence_exchange_suspicious_mailbox_right_delegation.toml +++ b/rules/integrations/o365/persistence_exchange_suspicious_mailbox_right_delegation.toml @@ -2,7 +2,7 @@ creation_date = "2021/05/17" integration = ["o365"] maturity = "production" -updated_date = "2025/04/01" +updated_date = "2025/04/23" [rule] author = ["Elastic", "Austin Songer"] @@ -63,8 +63,8 @@ type = "query" query = ''' event.dataset:o365.audit and event.provider:Exchange and event.action:Add-MailboxPermission and -o365.audit.Parameters.AccessRights:(FullAccess or SendAs or SendOnBehalf) and event.outcome:success and -not user.id : "NT AUTHORITY\SYSTEM (Microsoft.Exchange.ServiceHost)" +o365.audit.Parameters.AccessRights:(FullAccess or SendAs or SendOnBehalf) and event.outcome:success +and not user.id:("NT AUTHORITY\SYSTEM (Microsoft.Exchange.ServiceHost)" or "NT AUTHORITY\SYSTEM (Microsoft.Exchange.AdminApi.NetCore)" or "NT AUTHORITY\SYSTEM (w3wp)") ''' @@ -86,3 +86,15 @@ id = "TA0003" name = "Persistence" reference = "https://attack.mitre.org/tactics/TA0003/" +[rule.investigation_fields] +field_names = [ + "@timestamp", + "o365.audit.ObjectId", + "user.id", + "o365.audit.Parameters.User", + "o365.audit.Parameters.AccessRights", + "source.ip", + "user_agent.original", + "event.action", +] +