From aac3f3dec4e978a7595f6c39ce7d91e17150bf80 Mon Sep 17 00:00:00 2001 From: mvelazco Date: Fri, 22 Sep 2023 13:50:05 -0400 Subject: [PATCH] update story --- stories/office_365_detections.yml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/stories/office_365_detections.yml b/stories/office_365_detections.yml index a88ebbccf8..ba56585d37 100644 --- a/stories/office_365_detections.yml +++ b/stories/office_365_detections.yml @@ -1,14 +1,14 @@ name: Office 365 Detections id: 1a51dd71-effc-48b2-abc4-3e9cdb61e5b9 -version: 1 +version: 2 date: '2020-12-16' -author: Patrick Bareiss, Splunk -description: This story is focused around detecting Office 365 Attacks. -narrative: More and more companies are using Microsofts Office 365 cloud offering. - Therefore, we see more and more attacks against Office 365. This story provides - various detections for Office 365 attacks. +author: Patrick Bareiss, Mauricio Velazco, Splunk +description: Monitor for activities and anomalies indicative of potential threats within Office 365 environments. +narrative: Office 365 (O365) is Microsoft's cloud-based suite of productivity tools, encompassing email, collaboration platforms, and office applications, all integrated with Azure Active Directory for identity and access management. Given the centralized storage of sensitive organizational data within O365 and its widespread adoption, it has become a focal point for cybersecurity efforts. The platform's complexity, combined with its ubiquity, makes it both a valuable asset and a prime target for potential threats. As O365's importance grows, it increasingly becomes a target for attackers seeking to exploit organizational data and systems. Security teams should prioritize monitoring O365 not just because of the sensitive data it often holds, but also due to the myriad ways the platform can be exploited. Understanding and monitoring O365's security landscape is crucial for organizations to detect, respond to, and mitigate potential threats in a timely manner. references: - https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf +- https://attack.mitre.org/matrices/enterprise/cloud/office365/ +- https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-120a tags: analytic_story: Office 365 Detections category: