mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update o365_email_send_and_hard_delete_exfiltration_behavior.yml
This commit is contained in:
@@ -61,7 +61,7 @@ rba:
|
||||
score: 40
|
||||
threat_objects:
|
||||
- field: subject
|
||||
type: signature
|
||||
type: email_subject
|
||||
tags:
|
||||
analytic_story:
|
||||
- Office 365 Account Takeover
|
||||
|
||||
Reference in New Issue
Block a user