From 0e3e5ed2693c07afd6bd072fa8a22f67f4a5bd04 Mon Sep 17 00:00:00 2001 From: Isai <59296946+imays11@users.noreply.github.com> Date: Thu, 24 Apr 2025 00:49:06 -0400 Subject: [PATCH] [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4648) (cherry picked from commit b429be2bda3c131e6d8b451a9f39c6a39769c116) --- ...ge_suspicious_mailbox_right_delegation.toml | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/rules/integrations/o365/persistence_exchange_suspicious_mailbox_right_delegation.toml b/rules/integrations/o365/persistence_exchange_suspicious_mailbox_right_delegation.toml index e4563d0d5..2d53fa49a 100644 --- a/rules/integrations/o365/persistence_exchange_suspicious_mailbox_right_delegation.toml +++ b/rules/integrations/o365/persistence_exchange_suspicious_mailbox_right_delegation.toml @@ -2,7 +2,7 @@ creation_date = "2021/05/17" integration = ["o365"] maturity = "production" -updated_date = "2025/04/01" +updated_date = "2025/04/23" [rule] author = ["Elastic", "Austin Songer"] @@ -63,8 +63,8 @@ type = "query" query = ''' event.dataset:o365.audit and event.provider:Exchange and event.action:Add-MailboxPermission and -o365.audit.Parameters.AccessRights:(FullAccess or SendAs or SendOnBehalf) and event.outcome:success and -not user.id : "NT AUTHORITY\SYSTEM (Microsoft.Exchange.ServiceHost)" +o365.audit.Parameters.AccessRights:(FullAccess or SendAs or SendOnBehalf) and event.outcome:success +and not user.id:("NT AUTHORITY\SYSTEM (Microsoft.Exchange.ServiceHost)" or "NT AUTHORITY\SYSTEM (Microsoft.Exchange.AdminApi.NetCore)" or "NT AUTHORITY\SYSTEM (w3wp)") ''' @@ -86,3 +86,15 @@ id = "TA0003" name = "Persistence" reference = "https://attack.mitre.org/tactics/TA0003/" +[rule.investigation_fields] +field_names = [ + "@timestamp", + "o365.audit.ObjectId", + "user.id", + "o365.audit.Parameters.User", + "o365.audit.Parameters.AccessRights", + "source.ip", + "user_agent.original", + "event.action", +] +