Merge branch 'develop' into sunnyside

This commit is contained in:
Bhavin Patel
2025-03-28 12:22:09 -07:00
committed by GitHub
134 changed files with 959 additions and 652 deletions
@@ -114,3 +114,9 @@ example_log:
"Type": 4}], "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08", "UserId":
"rodsoto@rodsoto.onmicrosoft.com", "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
"UserType": 0, "Version": 1, "Workload": "AzureActiveDirectory"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -120,3 +120,9 @@ example_log:
"Type": 2}, {"ID": "Office 365 Exchange Online", "Type": 1}, {"ID": "00000002-0000-0ff1-ce00-000000000000",
"Type": 2}, {"ID": "https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com",
"Type": 4}], "TargetContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -90,3 +90,9 @@ example_log:
{"Name": "InheritanceType", "Value": "All"}], "RecordType": 1, "ResultStatus": "True",
"SessionId": "2be46662-a743-4a05-8744-c2f75f886512", "UserId": "pbareiss@rodsoto.onmicrosoft.com",
"UserKey": "10032001020A3408", "UserType": 2, "Version": 1, "Workload": "Exchange"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -112,3 +112,9 @@ example_log:
"Type": 2}, {"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72", "Type": 2}, {"ID": "User",
"Type": 2}, {"ID": "lowpriv@splunkresearch.onmicrosoft.com", "Type": 5}, {"ID":
"10032002CC029AE9", "Type": 3}], "TargetContextId": "d8211c86-3244-409b-8c4f-ae27ed34b4a5"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -114,3 +114,9 @@ example_log:
"Type": 2}, {"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72", "Type": 2}, {"ID": "User",
"Type": 2}, {"ID": "user2@contoso.onmicrosoft.com", "Type": 5}, {"ID": "10032002CC029AE9",
"Type": 3}], "TargetContextId": "48203edf-5d2c-45f2-8123-a368cc8b0e51"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -122,3 +122,9 @@ example_log:
"Type": 2}, {"ID": "Malicious11", "Type": 1}, {"ID": "e06366ca-8489-4748-b6a2-d7e4332f45c1",
"Type": 2}, {"ID": "e06366ca-8489-4748-b6a2-d7e4332f45c1", "Type": 4}], "TargetContextId":
"75243ab2-44f8-435c-a7a6-b479385df6d4"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -106,3 +106,9 @@ example_log:
"Type": 2}, {"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72", "Type": 2}, {"ID": "User",
"Type": 2}, {"ID": "victimUser@splunkresearch.onmicrosoft.com", "Type": 5}, {"ID":
"10032002CC029AE9", "Type": 3}], "TargetContextId": "bbad9541-eb53-4533-bcef-2b76182c3b75"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -114,3 +114,9 @@ example_log:
"Type": 2}, {"ID": "TestApp2", "Type": 1}, {"ID": "95106c0e-3519-450e-8e38-7f326d873454",
"Type": 2}, {"ID": "95106c0e-3519-450e-8e38-7f326d873454", "Type": 4}], "TargetContextId":
"9c00a473-1b2c-4bc2-9215-84df3f57aee5"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -106,3 +106,9 @@ example_log:
"Type": 5}, {"ID": "10037FFEA938FB92", "Type": 3}], "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "rodsoto@rodsoto.onmicrosoft.com", "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
"UserType": 0, "Version": 1, "Workload": "AzureActiveDirectory"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
+6
View File
@@ -100,3 +100,9 @@ example_log:
"SizeInBytes": 44572}, {"InternetMessageId": "<CH0PR18MB5530506D1B68B05A99A1109FF185A@CH0PR18MB5530.namprd18.prod.outlook.com>",
"SizeInBytes": 245068}], "Id": "LgAAAAC0AxwgOj/BRq9Bs1bhMPw/AQDh+UNSDzeHSLWfq+fr83BDAAAAAAEMAAAB",
"Path": "\\Inbox"}], "OperationCount": 4}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -114,3 +114,9 @@ example_log:
"ParentFolder": {"Id": "LgAAAABKe+NY5HVjRYWDqaJ5IKKFAQBQ11dzmT6LS6bQbkNDtISsAAAAAAEMAAAB",
"MemberRights": "FreeBusySimple", "MemberSid": "S-1-1-0", "MemberUpn": "Everyone",
"Name": "Inbox", "Path": "\\Inbox"}}}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -121,3 +121,9 @@ example_log:
Services LLC", "Type": 1}], "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
"UserId": "bpatel@rodsoto.onmicrosoft.com", "UserKey": "100320010208B5DC@rodsoto.onmicrosoft.com",
"UserType": 0, "Version": 1, "Workload": "AzureActiveDirectory"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
+6
View File
@@ -98,3 +98,9 @@ example_log:
"Identity", "Value": "bpatel@rodsoto.onmicrosoft.com"}], "RecordType": 1, "ResultStatus":
"True", "SessionId": "86a7cd7c-3f42-4b68-b670-4024b5461a80", "UserId": "pbareiss@rodsoto.onmicrosoft.com",
"UserKey": "10032001020A3408", "UserType": 2, "Version": 1, "Workload": "Exchange"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -122,3 +122,9 @@ example_log:
{"ID": "a2d68f8b-ab9f-47ac-934f-b966c3ac134f", "Type": 2}, {"ID": "Application",
"Type": 2}, {"ID": "TestApp2", "Type": 1}, {"ID": "95106c0e-3519-450e-8e38-7f326d873454",
"Type": 2}], "TargetContextId": "58aee3b9-7433-46a0-b54e-2429487992a0"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -105,3 +105,9 @@ example_log:
"Target": [{"ID": "AuthorizationPolicy_24484114-1daa-4700-aaf7-44ee5cbe5678", "Type":
2}, {"ID": "24484114-1daa-4700-aaf7-44ee5cbe5678", "Type": 2}, {"ID": "Other", "Type":
2}, {"ID": "Authorization Policy", "Type": 1}], "TargetContextId": "a417c578-c7ee-480d-a225-d48057e74df5"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
+6
View File
@@ -119,3 +119,9 @@ example_log:
"57e4bd36-9722-4a4a-9729-7203d8e00b72", "Type": 2}, {"ID": "User", "Type": 2}, {"ID":
"victim@splunkresearch1.onmicrosoft.com", "Type": 5}, {"ID": "10032002CC029AE9",
"Type": 3}], "TargetContextId": "99825d50-9544-4061-8e46-68923805cbf2"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
+6
View File
@@ -109,3 +109,9 @@ example_log:
"00000002-0000-0ff1-ce00-000000000000", "DeviceProperties": [{"Name": "OS", "Value":
"Windows10"}, {"Name": "BrowserType", "Value": "Firefox"}, {"Name": "SessionId",
"Value": "15e27956-79a0-45b2-9d02-60f48349f692"}], "ErrorNumber": "0"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
+6
View File
@@ -119,3 +119,9 @@ example_log:
"OS", "Value": "Windows10"}, {"Name": "BrowserType", "Value": "Chrome"}, {"Name":
"IsCompliantAndManaged", "Value": "False"}], "ErrorNumber": "50126", "LogonError":
"InvalidUserNameOrPassword"}'
output_fields:
- dest
- user
- src
- vendor_account
- vendor_product
@@ -1,4 +1,4 @@
name: Splunk CIM
name: Splunk Common Information Model (CIM)
id: d3dd8270-7e1c-4bcd-8f3a-e5ec4a0e740a
version: 1
date: '2025-01-14'
@@ -7,6 +7,6 @@ description: Data source object for Splunk CIM
source: not_applicable
sourcetype: not_applicable
supported_TA:
- name: Splunk_SA_CIM
- name: Splunk Common Information Model (CIM)
url: https://splunkbase.splunk.com/app/1621
version: 6.0.3
+1 -1
View File
@@ -16,7 +16,7 @@ sourcetype: stream:http
supported_TA:
- name: Splunk Stream
url: https://splunkbase.splunk.com/app/1809
version: 8.1.3
version: 8.1.5
fields:
- _time
- bytes
+1 -1
View File
@@ -16,7 +16,7 @@ sourcetype: stream:ip
supported_TA:
- name: Splunk Stream
url: https://splunkbase.splunk.com/app/1809
version: 8.1.3
version: 8.1.5
fields:
- _time
- action
+1 -1
View File
@@ -16,4 +16,4 @@ sourcetype: stream:tcp
supported_TA:
- name: Splunk Stream
url: https://splunkbase.splunk.com/app/1809
version: 8.1.3
version: 8.1.5
@@ -1,9 +1,9 @@
name: Cisco AI Defense Security Alerts by Application Name
id: 105e4a69-ec55-49fc-be1f-902467435ea8
version: 1
date: '2025-02-14'
version: 2
date: '2025-03-21'
author: Bhavin Patel, Splunk
status: experimental
status: production
type: Anomaly
description: The search surfaces alerts from the Cisco AI Defense product for potential attacks against the AI models running in your environment. This analytic identifies security events within Cisco AI Defense by examining event messages, actions, and policy names. It focuses on connections and applications associated with specific guardrail entities and ruleset types. By aggregating and analyzing these elements, the search helps detect potential policy violations and security threats, enabling proactive defense measures and ensuring network integrity.
data_source:
@@ -36,15 +36,19 @@ search: |-
severity="low", 25
)
| table model.model_name, user_id, event_action, application_id, application_name, severity, risk_score, policy_name, connection_name, guardrail_ruleset_type, guardrail_entity_name
|`cisco_ai_defense_security_alerts_by_application_name_filter`'
| `cisco_ai_defense_security_alerts_by_application_name_filter`
how_to_implement: To enable this detection, you need to ingest alerts from the Cisco AI Defense product. This can be done by using this app from splunkbase - Cisco Security Cloud and ingest alerts into the cisco:ai:defense sourcetype.
known_false_positives: False positives may vary based on Cisco AI Defense configuration; monitor and filter out the alerts that are not relevant to your environment.
references:
- https://www.robustintelligence.com/blog-posts/prompt-injection-attack-on-gpt-4
- https://docs.aws.amazon.com/prescriptive-guidance/latest/llm-prompt-engineering-best-practices/common-attacks.html
drilldown_searches:
- name: View risk events for the last 7 days for - "$application_id$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$application_id$" ) starthoursago=168 | stats count min(_time)
- name: View the detection results for - "$application_name$"
search: '%original_detection_search% | search application_name = "$application_name$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$application_name$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$application_name$") starthoursago=168 | stats count min(_time)
as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message)
as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
@@ -67,9 +71,10 @@ tags:
- Splunk Enterprise Security
- Splunk Cloud
security_domain: endpoint
manual_test: We are dynamically creating the risk_score field based on the severity of the alert in the SPL and that supersedes the risk score set in the detection.
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/cisco_ai_defense_alerts/cisco_ai_defense.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/cisco_ai_defense_alerts/cisco_ai_defense_alerts.json
source: cisco_ai_defense
sourcetype: cisco:ai:defense
@@ -1,6 +1,6 @@
name: High Number of Login Failures from a single source
id: 7f398cfb-918d-41f4-8db8-2e2474e02222
version: 6
version: 7
date: '2025-02-10'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
@@ -16,10 +16,13 @@ description: The following analytic detects multiple failed login attempts in Of
data_source:
- O365 UserLoginFailed
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed
record_type=AzureActiveDirectoryStsLogon | bucket span=5m _time | stats dc(_raw)
AS failed_attempts values(user) as user values(LogonError) as LogonError values(signature)
as signature values(UserAgent) as UserAgent by _time, src_ip | where failed_attempts
> 10 | `high_number_of_login_failures_from_a_single_source_filter`'
record_type=AzureActiveDirectoryStsLogon
| bucket span=5m _time
| stats dc(_raw) AS failed_attempts values(user) as user values(LogonError) as LogonError values(signature)
as signature values(UserAgent) as UserAgent values(dest) as dest values(vendor_account) as vendor_account values(vendor_product) as vendor_product
by _time, src_ip
| where failed_attempts > 10
| `high_number_of_login_failures_from_a_single_source_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. Adjust the threshold value to suit the specific
environment, as environments with naturally higher login failures might generate
@@ -1,6 +1,6 @@
name: O365 Add App Role Assignment Grant User
id: b2c81cc6-6040-11eb-ae93-0242ac130002
version: 6
version: 7
date: '2025-02-10'
author: Rod Soto, Splunk
status: production
@@ -14,11 +14,10 @@ description: The following analytic detects the addition of an application role
access to critical resources and data within the Office 365 environment.
data_source:
- O365 Add app role assignment grant to user.
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Add app
role assignment grant to user." | stats count min(_time) as firstTime max(_time)
as lastTime values(Actor{}.ID) as Actor.ID values(Actor{}.Type) as Actor.Type values(ModifiedProperties{}.Name)
as modified_properties_name by user dest ResultStatus Operation | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_add_app_role_assignment_grant_user_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Add app role assignment grant to user."
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_add_app_role_assignment_grant_user_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: The creation of a new Federation is not necessarily malicious,
@@ -42,8 +41,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $user$ has created a new federation setting $modified_properties_name$
on $dest$
message: User $user$ added a new app role assignment
risk_objects:
- field: user
type: user
@@ -1,6 +1,6 @@
name: O365 Added Service Principal
id: 1668812a-6047-11eb-ae93-0242ac130002
version: 7
version: 8
date: '2025-02-10'
author: Rod Soto, Splunk
status: production
@@ -15,11 +15,12 @@ description: The following analytic detects the addition of new service principa
leading to data breaches or further compromise.
data_source:
- O365
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="*Add
service principal*" OR (Operation = "*principal*" AND action = "created") | stats
count values(ModifiedProperties{}.NewValue) as new_value by src_user src_user_type
action Operation authentication_service Workload | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_added_service_principal_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="*Add service principal*" OR (Operation = "*principal*" AND action = "created")
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_added_service_principal_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: The creation of a new Federation is not necessarily malicious,
@@ -31,12 +32,12 @@ references:
- https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html
- https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack?hsLang=en
drilldown_searches:
- name: View the detection results for - "$src_user$"
search: '%original_detection_search% | search src_user = "$src_user$"'
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$src_user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_user$")
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
@@ -45,9 +46,9 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $src_user$ has created new service principal $new_value$ in AzureActiveDirectory
message: User $user$ has created new service principal in AzureActiveDirectory
risk_objects:
- field: src_user
- field: user
type: user
score: 42
threat_objects: []
@@ -1,6 +1,6 @@
name: O365 Admin Consent Bypassed by Service Principal
id: 8a1b22eb-50ce-4e26-a691-97ff52349569
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
data_source:
@@ -15,15 +15,20 @@ description: The following analytic identifies instances where a service princip
leading to unauthorized access or privilege escalation. If confirmed malicious,
this could allow an attacker to misuse automated processes to assign sensitive permissions,
compromising the security of the environment.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add
app role assignment to service principal.\" | eval len=mvcount('Actor{}.ID') | eval
userType = mvindex('Actor{}.ID',len-1) | eval roleId = mvindex('ModifiedProperties{}.NewValue',
0) | eval roleValue = mvindex('ModifiedProperties{}.NewValue', 1) | eval roleDescription
= mvindex('ModifiedProperties{}.NewValue', 2) | eval dest_user = mvindex('Target{}.ID',
0) | search userType = \"ServicePrincipal\" | eval src_user = user | stats count
earliest(_time) as firstTime latest(_time) as lastTime by src_user dest_user roleId
roleValue roleDescription | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`\
\ | `o365_admin_consent_bypassed_by_service_principal_filter`"
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add app role assignment to service principal.\"
| eval len=mvcount('Actor{}.ID')
| eval userType = mvindex('Actor{}.ID',len-1)
| eval roleId = mvindex('ModifiedProperties{}.NewValue', 0)
| eval roleValue = mvindex('ModifiedProperties{}.NewValue', 1)
| eval roleDescription = mvindex('ModifiedProperties{}.NewValue', 2)
| eval dest_user = mvindex('Target{}.ID', 0)
| search userType = \"ServicePrincipal\"
| eval src_user = user
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product dest_user roleId roleValue roleDescription
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_admin_consent_bypassed_by_service_principal_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Service Principals are sometimes configured to legitimately
@@ -50,8 +55,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: Service principal $src_user$ bypassed the admin consent process and granted
permissions to $dest_user$
message: Service principal $user$ bypassed the admin consent process and granted permissions to $dest_user$
risk_objects:
- field: dest_user
type: user
@@ -1,6 +1,6 @@
name: O365 Advanced Audit Disabled
id: 49862dd4-9cb2-4c48-a542-8c8a588d9361
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Michael Haag, Splunk
status: production
@@ -15,14 +15,19 @@ description: The following analytic detects instances where the O365 advanced au
it can blind security teams to potential malicious actions. If confirmed malicious,
attackers could operate within the user's mailbox or account with reduced risk of
detection, leading to unauthorized data access, data exfiltration, or account compromise.
search: "`o365_management_activity` Operation=\"Change user license.\" | eval property_name
= mvindex ('ExtendedProperties{}.Name', 1) | search property_name = \"extendedAuditEventCategory\"\
\ | eval additionalDetails = mvindex('ExtendedProperties{}.Value',0) | eval split_value=split(additionalDetails,
\"NewValue\") | eval possible_plan=mvindex(split_value, 1) | rex field=\"possible_plan\"\
\ \"DisabledPlans=\\[(?P<DisabledPlans>[^\\]]+)\\]\" | search DisabledPlans IN (\"\
*M365_ADVANCED_AUDITING*\") | stats min(_time) as firstTime max(_time) as lastTime
by Operation user object DisabledPlans | `security_content_ctime(firstTime)` |
`security_content_ctime(lastTime)` | `o365_advanced_audit_disabled_filter`"
search: "`o365_management_activity` Operation=\"Change user license.\"
| eval property_name = mvindex ('ExtendedProperties{}.Name', 1)
| search property_name = \"extendedAuditEventCategory\"
| eval additionalDetails = mvindex('ExtendedProperties{}.Value',0)
| eval split_value=split(additionalDetails,\"NewValue\")
| eval possible_plan=mvindex(split_value, 1)
| rex field=\"possible_plan\" \"DisabledPlans=\\[(?P<DisabledPlans>[^\\]]+)\\]\"
| search DisabledPlans IN (\"*M365_ADVANCED_AUDITING*\")
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product DisabledPlans object
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_advanced_audit_disabled_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Administrators might temporarily disable the advanced audit
@@ -1,6 +1,6 @@
name: O365 Application Available To Other Tenants
id: 942548a3-0273-47a4-8dbd-e5202437395c
version: 5
version: 6
date: '2025-02-10'
author: Steven Dick
status: production
@@ -12,16 +12,18 @@ description: The following analytic identifies the configuration of Azure Active
the O365 Universal Audit Log data source.
data_source:
- Office 365 Universal Audit Log
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"\
Add application.\",\"Update application.\") ModifiedProperties{}.Name=AvailableToOtherTenants
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add application.\",\"Update application.\") ModifiedProperties{}.Name=AvailableToOtherTenants
| eval result = case(match(mvindex('ModifiedProperties{}.NewValue',mvfind('ModifiedProperties{}.Name',\"\
AvailableToOtherTenants\")),\"false\"),\"removed\",true(),\"added\"), object_name=mvindex('Target{}.ID',
3), signature=Operation, object_attrs = \"AvailableToOtherTenants\", user = case(match(mvindex('Actor{}.ID',-1),\"\
User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"\
),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)) | search result = \"added\"\
\ | stats values(ActorIpAddress) as src, count, min(_time) as firstTime, max(_time)
as lastTime by signature, user, object, object_name, object_attrs, result | `security_content_ctime(firstTime)`\
\ | `security_content_ctime(lastTime)` | `o365_application_available_to_other_tenants_filter`"
AvailableToOtherTenants\")),\"false\"),\"removed\",true(),\"added\"), object_name=mvindex('Target{}.ID',
3), signature=Operation, object_attrs = \"AvailableToOtherTenants\", user = case(match(mvindex('Actor{}.ID',-1),\"\
User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"\
),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0))
| search result = \"added\"
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product object_attrs object_name
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_application_available_to_other_tenants_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Business approved changes by known administrators.
@@ -1,6 +1,6 @@
name: O365 Application Registration Owner Added
id: c068d53f-6aaa-4558-8011-3734df878266
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -16,11 +16,14 @@ description: The following analytic identifies instances where a new owner is as
an attacker could modify the application's settings, permissions, and behavior,
leading to unauthorized data access, privilege escalation, or the introduction of
malicious behavior within the application's operations.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add
owner to application.\" | eval app_id=mvindex('ModifiedProperties{}.NewValue', 0)
| eval app_displayName=mvindex('ModifiedProperties{}.NewValue', 1) | stats max(_time)
as lastTime values(ModifiedProperties{}.NewValue) by Operation, user, app_displayName,
object | `security_content_ctime(lastTime)` | `o365_application_registration_owner_added_filter`"
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add owner to application.\"
| eval app_id=mvindex('ModifiedProperties{}.NewValue', 0)
| eval app_displayName=mvindex('ModifiedProperties{}.NewValue', 1)
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product app_id app_displayName object
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_application_registration_owner_added_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Application owners may be added for legitimate reasons, filter
@@ -1,6 +1,6 @@
name: O365 ApplicationImpersonation Role Assigned
id: 49cdce75-f814-4d56-a7a4-c64ec3a481f2
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -15,9 +15,12 @@ description: The following analytic detects the assignment of the ApplicationImp
malicious, an attacker could gain unauthorized access to sensitive information,
manipulate mailbox data, and perform actions as a legitimate user, posing a severe
security risk to the organization.
search: '`o365_management_activity` Workload=Exchange Operation="New-ManagementRoleAssignment" Role=ApplicationImpersonation
| rename User as target_user | stats max(_time) as lastTime by Operation, user,
object, ObjectId, Role, target_user | `security_content_ctime(lastTime)` | `o365_applicationimpersonation_role_assigned_filter`'
search: '`o365_management_activity` Workload=Exchange Operation="New-ManagementRoleAssignment" Role=ApplicationImpersonation
| rename User as target_user
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product target_user
| `security_content_ctime(lastTime)`
| `o365_applicationimpersonation_role_assigned_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: While infrequent, the ApplicationImpersonation role may be
@@ -1,6 +1,6 @@
name: O365 Block User Consent For Risky Apps Disabled
id: 12a23592-e3da-4344-8545-205d3290647c
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -15,13 +15,15 @@ description: The following analytic detects when the "risk-based step-up consent
to grant consent to malicious applications. If confirmed malicious, attackers could
gain unauthorized access to user data and sensitive information, leading to data
breaches and further compromise within the organization.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
authorization policy.\" | eval index_number = if(mvfind('ModifiedProperties{}.Name',
\"AllowUserConsentForRiskyApps\") >= 0, mvfind('ModifiedProperties{}.Name', \"AllowUserConsentForRiskyApps\"\
), -1) | search index_number >= 0 | eval AllowUserConsentForRiskyApps = mvindex('ModifiedProperties{}.NewValue',index_number)
| where AllowUserConsentForRiskyApps like \"%true%\" | stats count min(_time) as
firstTime max(_time) as lastTime by user, Operation, AllowUserConsentForRiskyApps,
user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update authorization policy.\"
| eval index_number = if(mvfind('ModifiedProperties{}.Name',\"AllowUserConsentForRiskyApps\") >= 0, mvfind('ModifiedProperties{}.Name',\"AllowUserConsentForRiskyApps\"), -1)
| search index_number >= 0
| eval AllowUserConsentForRiskyApps = mvindex('ModifiedProperties{}.NewValue',index_number)
| where AllowUserConsentForRiskyApps like \"%true%\"
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product AllowUserConsentForRiskyApps
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_block_user_consent_for_risky_apps_disabled_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Bypass MFA via Trusted IP
id: c783dd98-c703-4252-9e8a-f19d9f66949e
version: 7
version: 8
date: '2025-02-10'
author: Bhavin Patel, Mauricio Velazco, Splunk
status: production
@@ -16,15 +16,17 @@ description: The following analytic identifies instances where new IP addresses
of the IP addition.
data_source:
- O365 Set Company Information.
search: '`o365_management_activity` Operation="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy
| rex max_match=100 field=ModifiedProperties{}.NewValue "(?<ip_addresses_new_added>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})"
| rex max_match=100 field=ModifiedProperties{}.OldValue "(?<ip_addresses_old>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})"
| eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0") | mvexpand
ip_addresses_new_added | where isnull(mvfind(ip_addresses_old,ip_addresses_new_added))
|stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old)
as ip_addresses_old by user ip_addresses_new_added Operation Workload vendor_account
status user_id action | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
`o365_bypass_mfa_via_trusted_ip_filter`'
search: '`o365_management_activity` Operation="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy
| rex max_match=100 field=ModifiedProperties{}.NewValue "(?<ip_addresses_new_added>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})"
| rex max_match=100 field=ModifiedProperties{}.OldValue "(?<ip_addresses_old>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})"
| eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0")
| mvexpand ip_addresses_new_added
| where isnull(mvfind(ip_addresses_old,ip_addresses_new_added))
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old) as ip_addresses_old by signature dest user src vendor_account vendor_product ip_addresses_new_added
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_bypass_mfa_via_trusted_ip_filter`'
how_to_implement: You must install Splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: Unless it is a special case, it is uncommon to continually
@@ -34,12 +36,12 @@ references:
- https://attack.mitre.org/techniques/T1562/007/
- https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings
drilldown_searches:
- name: View the detection results for - "$user_id$"
search: '%original_detection_search% | search user_id = "$user_id$"'
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user_id$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user_id$")
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
@@ -48,15 +50,13 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $user_id$ has added new IP addresses $ip_addresses_new_added$ to a
message: User $user$ has added new IP addresses $ip_addresses_new_added$ to a
list of trusted IPs to bypass MFA
risk_objects:
- field: user_id
- field: user
type: user
score: 42
threat_objects:
- field: ip_addresses_new_added
type: ip_address
threat_objects: []
tags:
analytic_story:
- Office 365 Persistence Mechanisms
@@ -1,6 +1,6 @@
name: O365 Compliance Content Search Exported
id: 2ce9f31d-ab4f-4179-b2b7-c77a9652e1d8
version: 6
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
@@ -14,10 +14,13 @@ description: The following analytic identifies when the results of a content sea
If confirmed malicious, an attacker could gain access to and exfiltrate sensitive
information, posing a severe risk to the organization's data security and compliance
posture.
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation="SearchExported"
| rename user_id as user | stats count earliest(_time) as firstTime latest(_time)
as lastTime by Operation, ObjectId, ExchangeLocations, user, Query |`security_content_ctime(firstTime)`
|`security_content_ctime(lastTime)` | `o365_compliance_content_search_exported_filter`'
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation="SearchExported"
| rename user_id as user
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product ExchangeLocations Query
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_compliance_content_search_exported_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Compliance content searche exports may be executed for legitimate
@@ -1,6 +1,6 @@
name: O365 Compliance Content Search Started
id: f4cabbc7-c19a-4e41-8be5-98daeaccbb50
version: 6
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
@@ -14,10 +14,13 @@ description: The following analytic detects when a content search is initiated w
unauthorized data access, potential data exfiltration, and compliance violations.
Monitoring this behavior helps ensure the integrity and security of organizational
data.
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=SearchCreated
| rename user_id as user | stats count earliest(_time) as firstTime latest(_time)
as lastTime by Operation, ObjectId, ExchangeLocations, user, Query |`security_content_ctime(firstTime)`
|`security_content_ctime(lastTime)` | `o365_compliance_content_search_started_filter`'
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=SearchCreated
| rename user_id as user
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product ExchangeLocations Query
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_compliance_content_search_started_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Compliance content searches may be executed for legitimate
@@ -1,6 +1,6 @@
name: O365 Concurrent Sessions From Different Ips
id: 58e034de-1f87-4812-9dc3-a4f68c7db930
version: 5
version: 6
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -15,10 +15,13 @@ description: The following analytic identifies user sessions in Office 365 acces
posing severe risks to organizational security.
data_source:
- O365 UserLoggedIn
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoggedIn
| stats min(_time) as firstTime max(_time) as lastTime values(src_ip) as ips values(user_agent)
as user_agents by Operation, user, SessionId | where mvcount(ips) > 1 | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_concurrent_sessions_from_different_ips_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoggedIn
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime values(src) as src by signature dest user vendor_account vendor_product
| where mvcount(src) > 1
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_concurrent_sessions_from_different_ips_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: Unknown
@@ -47,9 +50,7 @@ rba:
- field: user
type: user
score: 42
threat_objects:
- field: ips
type: ip_address
threat_objects: []
tags:
analytic_story:
- Office 365 Account Takeover
@@ -1,6 +1,6 @@
name: O365 Cross-Tenant Access Change
id: 7c0fa490-12b0-4d0b-b9f5-e101d1e0e06f
version: 4
version: 5
date: '2024-11-14'
author: Steven Dick
status: production
@@ -13,13 +13,14 @@ description: The following analytic identifies when cross-tenant access/synchron
data_source:
- Office 365 Universal Audit Log
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"\
Add a partner to cross-tenant access setting.\",\"Delete partner specific cross-tenant
access setting.\") | eval user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)) | stats
values(Workload) as category, values(ClientIP) as src, values(ModifiedProperties{}.Name)
as object_name, values(ModifiedProperties{}.NewValue) as object_attrs, count, min(_time)
as firstTime, max(_time) as lastTime by Id,user,Operation | rename Operation as
signature, Id as signature_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
Add a partner to cross-tenant access setting.\",\"Delete partner specific cross-tenant
access setting.\")
| eval user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0))
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account vendor_product signature signature_id
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_cross_tenant_access_change_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -44,8 +45,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: The user [$user$] changed the Azure cross-tenant access settings for $object_name$
$object_attrs$ [$signature$]
message: The user [$user$] changed the Azure cross-tenant access settings
risk_objects:
- field: user
type: user
+9 -7
View File
@@ -1,6 +1,6 @@
name: O365 Disable MFA
id: c783dd98-c703-4252-9e8a-f19d9f5c949e
version: 5
version: 6
date: '2024-11-14'
author: Rod Soto, Splunk
status: production
@@ -16,11 +16,13 @@ description: The following analytic identifies instances where Multi-Factor Auth
related to the affected account.
data_source:
- O365 Disable Strong Authentication.
search: '`o365_management_activity` Operation="Disable Strong Authentication." | stats
count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation
UserId ResultStatus object | rename UserType AS user_type, Operation AS action,
UserId AS src_user, object AS user, ResultStatus AS result | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_disable_mfa_filter`'
search: '`o365_management_activity` Operation="Disable Strong Authentication."
| rename UserId as user object as src_user
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product src_user
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_disable_mfa_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: Unless it is a special case, it is uncommon to disable MFA
@@ -42,7 +44,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $src_user$ has executed an operation $action$ for user $user$
message: User $src_user$ has executed an operation $signature$ for user $user$
risk_objects:
- field: user
type: user
+21 -26
View File
@@ -1,7 +1,7 @@
name: O365 DLP Rule Triggered
id: 63a8a537-36fd-4aac-a3ea-1a96afd2c871
version: 5
date: '2024-11-14'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: Anomaly
@@ -9,22 +9,20 @@ description: The following analytic detects when Microsoft Office 365 Data Loss
(DLP) rules have been triggered. DLP rules can be configured for any number of security,
regulatory, or business compliance reasons, as such this analytic will only be as
accurate as the upstream DLP configuration. Detections from this analytic should
be evaluated thoroughly to determine what, if any, security relevance the underlying
be evaluated thoroughly to de termine what, if any, security relevance the underlying
DLP events contain.
data_source:
- Office 365 Universal Audit Log
search: "`o365_management_activity` Operation=DLPRuleMatch | eval recipient = 'ExchangeMetaData.To{}',
signature_id = 'ExchangeMetaData.UniqueID', signature = 'PolicyDetails{}.Rules{}.RuleName'
, src_user = UserId, reason ='PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.SensitiveInformationTypeName',
result='PolicyDetails{}.Rules{}.Actions{}', file_name=case(NOT match('PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.Location',\"\
Message Body\"),'PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.Location')
| stats min(_time) as firstTime max(_time) as lastTime values(signature) as signature
values(file_name) as file_name values(ExchangeMetaData.Subject) AS subject values(Workload)
as app values(result) as result by src_user,recipient,signature_id,reason | `o365_dlp_rule_triggered_filter`
| stats count min(firstTime) as firstTime max(lastTime) as lastTime values(*) AS
* by src_user,signature_id | eval action = CASE(match(result,\"Halt\"),\"blocked\"\
,isnotnull(result),\"alert\",true(),\"allow\") |`security_content_ctime(firstTime)`\
\ |`security_content_ctime(lastTime)`"
search: '`o365_management_activity` Operation=DLPRuleMatch | eval recipient = ''ExchangeMetaData.To{}'',
signature_id = ''ExchangeMetaData.UniqueID'', signature = ''PolicyDetails{}.Rules{}.RuleName''
, src_user = UserId, reason =''PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.SensitiveInformationTypeName'',
result=''PolicyDetails{}.Rules{}.Actions{}'', file_name=case(NOT match(''PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.Location'',"Message
Body"),''PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.Location'')
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime values(signature)
as signature values(file_name) as file_name values(ExchangeMetaData.Subject) AS
subject values(Workload) as app values(result) as result by action dest user src
vendor_account vendor_product src_user recipient signature_id reason | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_dlp_rule_triggered_filter` '
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. You must deploy DLP rules through O365 security
and compliance functions.
@@ -33,12 +31,12 @@ known_false_positives: WIll depending on accuracy of DLP rules, these can be noi
references:
- https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
drilldown_searches:
- name: View the detection results for - "$src_user$"
search: '%original_detection_search% | search src_user = "$src_user$"'
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$src_user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_user$")
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
@@ -47,14 +45,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $src_user$ triggered a Microsoft Office DLP rule.
message: User $user$ triggered a Microsoft Office DLP rule.
risk_objects:
- field: src_user
- field: user
type: user
score: 20
threat_objects:
- field: recipient
type: email_address
threat_objects: []
tags:
analytic_story:
- Data Exfiltration
@@ -70,7 +66,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,6 +1,6 @@
name: O365 Elevated Mailbox Permission Assigned
id: 2246c142-a678-45f8-8546-aaed7e0efd30
version: 6
version: 7
date: '2025-02-10'
author: Patrick Bareiss, Mauricio Velazco, Splunk
data_source: []
@@ -14,11 +14,13 @@ description: The following analytic identifies the assignment of elevated mailbo
over mailboxes, which could lead to data exfiltration or privilege escalation. If
confirmed malicious, attackers could gain extensive access to sensitive email data
and potentially manipulate mailbox settings, posing a severe security risk.
search: '`o365_management_activity` Workload=Exchange Operation=Add-MailboxPermission
| search (AccessRights=FullAccess OR AccessRights=ChangePermission OR AccessRights=ChangeOwner)
| rename Identity AS dest_user | stats count earliest(_time) as firstTime latest(_time)
as lastTime by user dest_user Operation AccessRights |`security_content_ctime(firstTime)`
|`security_content_ctime(lastTime)` | `o365_elevated_mailbox_permission_assigned_filter`'
search: '`o365_management_activity` Workload=Exchange Operation=Add-MailboxPermission (AccessRights=FullAccess OR AccessRights=ChangePermission OR AccessRights=ChangeOwner)
| rename Identity AS dest_user
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product dest_user
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_elevated_mailbox_permission_assigned_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: FullAccess mailbox delegation may be assigned for legitimate
@@ -1,7 +1,7 @@
name: O365 Email Access By Security Administrator
id: c6998a30-fef4-4e89-97ac-3bb0123719b4
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -12,9 +12,9 @@ description: The following analytic identifies when a user with sufficient acces
data_source:
- Office 365 Universal Audit Log
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AdminMailAccess
| stats values(Workload) as category, values(MailboxId) as user, values(Operation)
as signature, count, min(_time) as firstTime, max(_time) as lastTime by InternetMessageId,
UserId | rename InternetMessageId as signature_id, UserId as src_user | `security_content_ctime(firstTime)`
| rename InternetMessageId as signature_id, UserId as src_user | fillnull | stats
count min(_time) as firstTime max(_time) as lastTime by signature dest user src
vendor_account vendor_product src_user signature_id | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_email_access_by_security_administrator_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. Threat Explorer is a premium feature with
@@ -64,7 +64,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,7 +1,7 @@
name: O365 Email Reported By Admin Found Malicious
id: 94396c3e-7728-422a-9956-e4b77b53dbdf
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -13,12 +13,11 @@ description: The following analytic detects when an email manually submitted to
data_source:
- Office 365 Universal Audit Log
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AdminSubmission
| search RescanVerdict IN (Phish,Malware) | stats values(Subject) as subject, values(RescanVerdict)
as result, values(SenderIP) as src, values(P2Sender) as sender, values(P1Sender)
as src_user, values(Recipients{}) as user, count min(_time) as firstTime, max(_time)
as lastTime, by Id,Operation,UserId | rename Name as signature, Id as signature_id,
UserId as o365_adminuser | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `o365_email_reported_by_admin_found_malicious_filter`'
| search RescanVerdict IN (Phish,Malware) | rename Id as signature_id, SenderIP
as src, Recipients{} as dest_user, P1Sender as src_user | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account vendor_product
signature signature_id dest_user src_user Subject SubmissionContent | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_email_reported_by_admin_found_malicious_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: Administrators that submit known phishing training exercises.
@@ -39,8 +38,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: O365 security admin $o365_adminuser$ manually reported a suspicious email
from $src_user$
message: O365 security admin $user$ manually reported a suspicious email from $src_user$
risk_objects:
- field: src_user
type: user
@@ -49,7 +47,7 @@ rba:
type: user
score: 50
threat_objects:
- field: subject
- field: Subject
type: email_subject
tags:
analytic_story:
@@ -67,7 +65,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,7 +1,7 @@
name: O365 Email Reported By User Found Malicious
id: 7698b945-238e-4bb9-b172-81f5ca1685a1
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -12,14 +12,14 @@ description: The following analytic detects when an email submitted to Microsoft
that returns a Phish or Malware verdict upon submission.
data_source:
- Office 365 Universal Audit Log
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AlertEntityGenerated
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AlertEntityGenerated
Name="Email reported by user as*" | fromjson Data | rename _raw AS temp etps AS
_raw | extract pairdelim=";" kvdelim=":" | rename _raw AS etps temp AS _raw | search
RescanVerdict IN (Phish,Malware) | rex field=tsd "\<(?<src_user>.+)\>" | eval src_user
= case(isnull(src_user),tsd,true(),src_user) | stats count min(_time) as firstTime
max(_time) as lastTime values(ms) as subject values(RescanVerdict) as result values(tsd)
as sender values(src_user) as src_user by AlertId,AlertEntityId,Operation,Name |
rename Name as signature, AlertId as signature_id, AlertEntityId as user | `security_content_ctime(firstTime)`
= case(isnull(src_user),tsd,true(),src_user) | rename Name as signature, AlertId
as signature_id, AlertEntityId as user, tsd as sender, ms as subject | fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account
vendor_product signature signature_id src_user sender subject | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_email_reported_by_user_found_malicious_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. You must deploy/allow the usage of the Microsoft
@@ -42,7 +42,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: The user $user$ reported an email classified as $result$ from $src_user$
message: The user $user$ reported an email classified from $src_user$
risk_objects:
- field: src_user
type: user
@@ -69,7 +69,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,7 +1,7 @@
name: O365 Email Security Feature Changed
id: 4d28013d-3a0f-4d65-a33f-4e8009fee0ae
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -13,10 +13,11 @@ description: The following analytic identifies when specific O365 advanced secur
data_source:
- Office 365 Universal Audit Log
search: '`o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*")
Operation IN ("*AntiPhish*","*SafeLink*","*SafeAttachment*","*Malware*") | stats
values(ObjectId) as object, min(_time) as firstTime, max(_time) as lastTime, count by
Id, UserId, Operation | rename Id as object_id, UserId as user, Operation as signature
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_email_security_feature_changed_filter`'
Operation IN ("*AntiPhish*","*SafeLink*","*SafeAttachment*","*Malware*") | rename
Id as object_id, UserId as user, Operation as signature, ObjectId as object | fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account
vendor_product signature object_id object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_email_security_feature_changed_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Administrators might alter features for troubleshooting, performance
@@ -61,7 +62,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,7 +1,7 @@
name: O365 Email Suspicious Behavior Alert
id: 85c7555a-05af-4322-81aa-76b4ddf52baa
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -16,8 +16,9 @@ data_source:
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AlertEntityGenerated
Name IN ("Suspicious email sending patterns detected","User restricted from sending
email","Suspicious Email Forwarding Activity","Email sending limit exceeded") |
fromjson Data | stats count min(_time) as firstTime max(_time) as lastTime by AlertId,ObjectId,Operation,Name
| rename Name as signature, AlertId as signature_id, ObjectId as user | `security_content_ctime(firstTime)`
fromjson Data | rename Name as signature, AlertId as signature_id, ObjectId as user
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by dest
user src vendor_account vendor_product signature signature_id | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_email_suspicious_behavior_alert_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. The alerts must be enabled in the o365 security
@@ -63,7 +64,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,6 +1,6 @@
name: O365 Email Transport Rule Changed
id: 11ebb7c2-46bd-41c9-81e1-d0b4b34583a2
version: 1
version: 2
date: '2025-01-15'
author: Steven Dick
status: production
@@ -11,8 +11,8 @@ data_source:
search: |-
`o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*TransportRule"
| eval object_name = case('Parameters{}.Name'=="Name",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Name$")),true(),ObjectId), object_id = case('Parameters{}.Name'=="Identity",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Identity$")),true(),Id)
| stats values(object_name) as object_name, min(_time) as firstTime, max(_time) as lastTime, count by object_id, UserId, Operation
| rename UserId as user, Operation as signature
| stats values(object_name) as object_name, min(_time) as firstTime, max(_time) as lastTime, count by object_id, UserId, Operation, signature
| rename UserId as user
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_email_transport_rule_changed_filter`
@@ -1,6 +1,6 @@
name: O365 Excessive Authentication Failures Alert
id: d441364c-349c-453b-b55f-12eccab67cf9
version: 5
version: 6
date: '2024-11-14'
author: Rod Soto, Splunk
status: production
@@ -13,11 +13,12 @@ description: The following analytic identifies an excessive number of authentica
this activity could lead to unauthorized access, data breaches, or further exploitation
within the environment.
data_source: []
search: '`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=*
status=failure | stats count earliest(_time) AS firstTime latest(_time) AS lastTime
values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS
UserAgent values(status) AS status values(src_ip) AS src_ip by user | where count
> 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: '`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=* status=failure
| stats count earliest(_time) AS firstTime latest(_time) AS lastTime values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS
user_agent values(status) AS status values(src_ip) AS src values(signature) as signature by user vendor_account vendor_product dest
| where count > 10
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_excessive_authentication_failures_alert_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
@@ -41,13 +42,13 @@ drilldown_searches:
latest_offset: $info_max_time$
rba:
message: User $user$ has caused excessive number of authentication failures from
$src_ip$ using UserAgent $UserAgent$.
$src$ using UserAgent $user_agent$.
risk_objects:
- field: user
type: user
score: 64
threat_objects:
- field: src_ip
- field: src
type: ip_address
tags:
analytic_story:
@@ -1,6 +1,6 @@
name: O365 Excessive SSO logon errors
id: 8158ccc4-6038-11eb-ae93-0242ac130002
version: 6
version: 7
date: '2024-11-14'
author: Rod Soto, Splunk
status: production
@@ -14,10 +14,11 @@ description: The following analytic detects accounts experiencing a high number
movement within the organization.
data_source:
- O365 UserLoginFailed
search: '`o365_management_activity` Workload=AzureActiveDirectory LogonError=*Sso*
Operation=UserLoginFailed | stats count min(_time) as firstTime max(_time) as lastTime
values(user) as user by src_ip signature user_agent authentication_service action|
where count >= 5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: '`o365_management_activity` Workload=AzureActiveDirectory LogonError=*Sso* Operation=UserLoginFailed
| stats count min(_time) as firstTime max(_time) as lastTime values(user) as user by src vendor_account vendor_product dest signature user_agent
| where count >= 5
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_excessive_sso_logon_errors_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
@@ -40,13 +41,13 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: Excessive number of SSO logon errors from $src_ip$ using UserAgent $user_agent$.
message: Excessive number of SSO logon errors from $src$ using UserAgent $user_agent$.
risk_objects:
- field: user
type: user
score: 64
threat_objects:
- field: src_ip
- field: src
type: ip_address
tags:
analytic_story:
@@ -1,6 +1,6 @@
name: O365 External Guest User Invited
id: 8c6d52ec-d5f2-4b2f-8ba1-f32c047a71fa
version: 4
version: 5
date: '2024-11-14'
author: Steven Dick
status: production
@@ -16,15 +16,19 @@ description: The following analytic identifies the invitation of an external gue
source.
data_source:
- Office 365 Universal Audit Log
search: "`o365_management_activity` Workload=AzureActiveDirectory AND Operation=\"\
Add user*\" AND ModifiedProperties{}.NewValue=\"[*Guest*]\" AND ModifiedProperties{}.NewValue=\"\
[*Invitation*]\" | eval user = (mvindex('ModifiedProperties{}.NewValue',5)), src_user
= case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)) | rex
field=user \"(?<user>[\\\\w\\\\.-]+@[\\\\w-]+\\\\.[\\\\w-]{2,4})\" | stats values(user)
as user, min(_time) as firstTime, max(_time) as lastTime, count by Operation,Id,src_user
| rename Operation as signature, Id as signature_id | `security_content_ctime(firstTime)`\
\ | `security_content_ctime(lastTime)` | `o365_external_guest_user_invited_filter`"
search: "`o365_management_activity` Workload=AzureActiveDirectory AND Operation=\"Add user*\" AND ModifiedProperties{}.NewValue=\"[*Guest*]\" AND ModifiedProperties{}.NewValue=\"[*Invitation*]\"
| eval user = (mvindex('ModifiedProperties{}.NewValue',5)), src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0))
| rex
field=user \"(?<user>
[ \\w\\.-]+@
[ \\w-]+\\.
[ \\w-]{2,4})\"
| rename Operation as signature, Id as signature_id
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account vendor_product signature signature_id src_user
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_external_guest_user_invited_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Administrator may legitimately invite external guest users.
@@ -1,6 +1,6 @@
name: O365 External Identity Policy Changed
id: 29af1725-7a72-4d2d-8a18-e697e79a62d3
version: 4
version: 5
date: '2024-11-14'
author: Steven Dick
status: production
@@ -15,23 +15,27 @@ description: The following analytic identifies when changes are made to the exte
by Abusing External Identities`.
data_source:
- Office 365 Universal Audit Log
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
policy.\" Target{}.ID=\"B2BManagementPolicy\" | eval object_attrs = mvindex('ModifiedProperties{}.NewValue',0),
object_attrs_old = mvindex('ModifiedProperties{}.OldValue',0), object_name = mvindex('Target{}.ID',3),
signature=Operation, user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)) | spath
input=object_attrs_old output=B2BOld path={} | spath input=B2BOld | rename B2BManagementPolicy.*
as B2BManagementPolicyOld.* | spath input=object_attrs output=B2BNew path={} | spath
input=B2BNew | eval object_attrs = 'B2BManagementPolicy.InvitationsAllowedAndBlockedDomainsPolicy.AllowedDomains{}'
, object_attrs_old = 'B2BManagementPolicyOld.InvitationsAllowedAndBlockedDomainsPolicy.AllowedDomains{}'
| eval diff_add=mvmap(object_attrs,if(isnull(mvfind(object_attrs_old,object_attrs)),object_attrs,null))
| eval diff_remove=mvmap(object_attrs_old,if(isnull(mvfind(object_attrs,object_attrs_old)),object_attrs_old,null))
| eval result = case(isnotnull(diff_add),\"Added \".mvjoin(diff_add,\",\"),isnotnull(diff_remove),\"\
Removed \".mvjoin(diff_remove,\",\")), action = case(isnotnull(diff_add),\"created\"\
,isnotnull(diff_remove),\"deleted\") | stats values(object_attrs) as object_attrs,
values(action) as action, values(result) as result, values(B2BManagementPolicy*)
as B2BManagementPolicy*, count, min(_time) as firstTime, max(_time) as lastTime
by user,signature,object_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update policy.\" Target{}.ID=\"B2BManagementPolicy\"
| eval object_attrs = mvindex('ModifiedProperties{}.NewValue',0),
object_attrs_old = mvindex('ModifiedProperties{}.OldValue',0), object_name = mvindex('Target{}.ID',3),
signature=Operation, user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),
mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0))
| spath input=object_attrs_old output=B2BOld path={}
| spath input=B2BOld
| rename B2BManagementPolicy.* as B2BManagementPolicyOld.*
| spath input=object_attrs output=B2BNew path={}
| spath input=B2BNew
| eval object_attrs = 'B2BManagementPolicy.InvitationsAllowedAndBlockedDomainsPolicy.AllowedDomains{}'
, object_attrs_old = 'B2BManagementPolicyOld.InvitationsAllowedAndBlockedDomainsPolicy.AllowedDomains{}'
| eval diff_add=mvmap(object_attrs,if(isnull(mvfind(object_attrs_old,object_attrs)),object_attrs,null))
| eval diff_remove=mvmap(object_attrs_old,if(isnull(mvfind(object_attrs,object_attrs_old)),object_attrs_old,null))
| eval result = case(isnotnull(diff_add),\"Added \".mvjoin(diff_add,\",\"),isnotnull(diff_remove),\"Removed \".mvjoin(diff_remove,\",\")), action = case(isnotnull(diff_add),\"created\",isnotnull(diff_remove),\"deleted\")
| stats values(object_attrs) as object_attrs,
values(action) as action, values(result) as result, values(B2BManagementPolicy*)
as B2BManagementPolicy*, count, min(_time) as firstTime, max(_time) as lastTime
by user signature object_name dest vendor_account vendor_product
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_external_identity_policy_changed_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -54,7 +58,7 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $user$ changed the external identity [$object_name$] policy - $result$
message: User $user$ changed the external identity [$object_name$] policy
risk_objects:
- field: user
type: user
@@ -1,6 +1,6 @@
name: O365 File Permissioned Application Consent Granted by User
id: 6c382336-22b8-4023-9b80-1689e799f21f
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -15,13 +15,17 @@ description: The following analytic identifies instances where a user in the Off
is malicious or overly permissive. If confirmed malicious, this could lead to data
breaches, data loss, or unauthorized data manipulation, necessitating immediate
investigation to validate the application's legitimacy and assess potential risks.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent
to application.\" ResultStatus=Success | eval admin_consent =mvindex('ModifiedProperties{}.NewValue',
0) | search admin_consent=False | eval permissions =mvindex('ModifiedProperties{}.NewValue',
4) | rex field=permissions \"Scope: (?<Scope>[^,]+)\" | makemv delim=\" \" Scope
| search Scope IN (\"Files.Read\", \"Files.Read.All\", \"Files.ReadWrite\", \"Files.ReadWrite.All\"\
, \"Files.ReadWrite.AppFolder\") | stats max(_time) as lastTime values(Scope) by
Operation, user, object, ObjectId | `security_content_ctime(lastTime)` | `o365_file_permissioned_application_consent_granted_by_user_filter`"
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent to application.\" ResultStatus=Success
| eval admin_consent =mvindex('ModifiedProperties{}.NewValue',0)
| search admin_consent=False
| eval permissions =mvindex('ModifiedProperties{}.NewValue',4)
| rex field=permissions \"Scope:(?<Scope>[^,]+)\"
| makemv delim=\" \" Scope
| search Scope IN (\"Files.Read\", \"Files.Read.All\", \"Files.ReadWrite\", \"Files.ReadWrite.All\", \"Files.ReadWrite.AppFolder\")
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime values(Scope) as Scope by signature dest user src vendor_account vendor_product object ObjectId
| `security_content_ctime(lastTime)`
| `o365_file_permissioned_application_consent_granted_by_user_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: OAuth applications that require file permissions may be legitimate,
@@ -1,6 +1,6 @@
name: O365 FullAccessAsApp Permission Assigned
id: 01a510b3-a6ac-4d50-8812-7e8a3cde3d79
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -15,13 +15,15 @@ description: The following analytic detects the assignment of the 'full_access_a
Office 365 operations, including access to all mailboxes and the ability to send
mail as any user. If confirmed malicious, this could lead to unauthorized data access,
exfiltration, or account compromise. Immediate investigation is required.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
application.\" | eval newvalue = mvindex('ModifiedProperties{}.NewValue',0) | spath
input=newvalue | search \"{}.ResourceAppId\"=\"00000002-0000-0ff1-ce00-000000000000\"\
\ \"{}.RequiredAppPermissions{}.EntitlementId\"=\"dc890d15-9560-4a4c-9b7f-a736ec74ec40\"\
\ | eval Permissions = '{}.RequiredAppPermissions{}.EntitlementId' | stats count
earliest(_time) as firstTime latest(_time) as lastTime values(Permissions) by user,
object, user_agent, Operation | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update application.\"
| eval newvalue = mvindex('ModifiedProperties{}.NewValue',0)
| spath input=newvalue
| search \"{}.ResourceAppId\"=\"00000002-0000-0ff1-ce00-000000000000\"\"{}.RequiredAppPermissions{}.EntitlementId\"=\"dc890d15-9560-4a4c-9b7f-a736ec74ec40\"
| eval Permissions = '{}.RequiredAppPermissions{}.EntitlementId'
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime values(Scope) as Scope by signature dest user src vendor_account vendor_product object user_agent
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_fullaccessasapp_permission_assigned_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 High Number Of Failed Authentications for User
id: 31641378-2fa9-42b1-948e-25e281cb98f7
version: 6
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -15,9 +15,12 @@ description: The following analytic identifies an O365 account experiencing more
access to the O365 environment, potentially compromising sensitive emails, documents,
and other data. Prompt investigation and action are crucial to prevent unauthorized
access and data breaches.
search: '`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon
Workload=AzureActiveDirectory | bucket span=5m _time | stats dc(_raw) AS failed_attempts values(src_ip)
as src_ip by user, _time | where failed_attempts > 10 | `o365_high_number_of_failed_authentications_for_user_filter`'
search: '`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon Workload=AzureActiveDirectory
| bucket span=5m _time
| fillnull
| stats dc(_raw) AS failed_attempts values(src_ip) as src by signature user _time dest vendor_account vendor_product
| where failed_attempts > 10
| `o365_high_number_of_failed_authentications_for_user_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Although unusual, users who have lost their passwords may trigger
@@ -47,7 +50,7 @@ rba:
type: user
score: 35
threat_objects:
- field: src_ip
- field: src
type: ip_address
tags:
analytic_story:
@@ -1,6 +1,6 @@
name: O365 High Privilege Role Granted
id: e78a1037-4548-4072-bb1b-ad99ae416426
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -15,12 +15,15 @@ description: The following analytic detects when high-privilege roles such as "E
over critical resources and data. If confirmed malicious, this could enable attackers
to gain significant control over O365 resources, access, modify, or delete critical
data, and compromise the overall security and functionality of the O365 environment.
search: "`o365_management_activity` Operation=\"Add member to role.\" Workload=AzureActiveDirectory
| eval role_id = mvindex('ModifiedProperties{}.NewValue',2) | eval role_name = mvindex('ModifiedProperties{}.NewValue',1)
| where role_id IN (\"29232cdf-9323-42fd-ade2-1d097af3e4de\", \"f28a1f50-f6e7-4571-818b-6a12f2af6b6c\"\
, \"62e90394-69f5-4237-9190-012177145e10\") | stats earliest(_time) as firstTime
latest(_time) as lastTime by user Operation ObjectId role_name | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_high_privilege_role_granted_filter`"
search: "`o365_management_activity` Operation=\"Add member to role.\" Workload=AzureActiveDirectory
| eval role_id = mvindex('ModifiedProperties{}.NewValue',2)
| eval role_name = mvindex('ModifiedProperties{}.NewValue',1)
| where role_id IN (\"29232cdf-9323-42fd-ade2-1d097af3e4de\", \"f28a1f50-f6e7-4571-818b-6a12f2af6b6c\", \"62e90394-69f5-4237-9190-012177145e10\")
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product ObjectId role_name role_id
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_high_privilege_role_granted_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Privilege roles may be assigned for legitimate purposes, filter
@@ -1,6 +1,6 @@
name: O365 Mail Permissioned Application Consent Granted by User
id: fddad083-cdf5-419d-83c6-baa85e329595
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -16,13 +16,16 @@ description: The following analytic identifies instances where a user grants con
data access, email forwarding, or sending malicious emails from the compromised
account. Validating the legitimacy of the application and consent context is crucial
to prevent data breaches.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent
to application.\" ResultStatus=Success | eval admin_consent =mvindex('ModifiedProperties{}.NewValue',
0) | search admin_consent=False | eval permissions =mvindex('ModifiedProperties{}.NewValue',
4) | rex field=permissions \"Scope: (?<Scope>[^,]+)\" | makemv delim=\" \" Scope
| search Scope IN (\"Mail.Read\", \"Mail.ReadBasic\", \"Mail.ReadWrite\", \"Mail.Read.Shared\"\
, \"Mail.ReadWrite.Shared\", \"Mail.Send\", \"Mail.Send.Shared\") | stats max(_time)
as lastTime values(Scope) by Operation, user, object, ObjectId | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent to application.\" ResultStatus=Success
| eval admin_consent =mvindex('ModifiedProperties{}.NewValue',0)
| search admin_consent=False
| eval permissions =mvindex('ModifiedProperties{}.NewValue',4)
| rex field=permissions \"Scope:(?<Scope>[^,]+)\"
| makemv delim=\" \" Scope
| search Scope IN (\"Mail.Read\", \"Mail.ReadBasic\", \"Mail.ReadWrite\", \"Mail.Read.Shared\", \"Mail.ReadWrite.Shared\", \"Mail.Send\", \"Mail.Send.Shared\")
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime values(Scope) as Scope by signature dest user src vendor_account vendor_product object ObjectId
| `security_content_ctime(lastTime)`
| `o365_mail_permissioned_application_consent_granted_by_user_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Mailbox Email Forwarding Enabled
id: 0b6bc75c-05d1-4101-9fc3-97e706168f24
version: 5
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Mauricio Velazco, Splunk
data_source: []
@@ -14,12 +14,16 @@ description: The following analytic identifies instances where email forwarding
to data exfiltration and unauthorized access to sensitive information. If confirmed
malicious, attackers could intercept and redirect emails, potentially compromising
confidential communications and leading to data breaches.
search: "`o365_management_activity` Operation=Set-Mailbox | eval match1=mvfind('Parameters{}.Name',
\"ForwardingAddress\") | eval match2=mvfind('Parameters{}.Name', \"ForwardingSmtpAddress\"\
) | where match1>= 0 OR match2>= 0 | eval ForwardTo=coalesce(ForwardingAddress,
ForwardingSmtpAddress) | search ForwardTo!=\"\" | rename user_id as user | stats
count earliest(_time) as firstTime latest(_time) as lastTime values(ForwardTo) as
ForwardTo by user ObjectId |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)`
search: "`o365_management_activity` Operation=Set-Mailbox
| eval match1=mvfind('Parameters{}.Name',\"ForwardingAddress\")
| eval match2=mvfind('Parameters{}.Name', \"ForwardingSmtpAddress\")
| where match1>= 0 OR match2>= 0
| eval ForwardTo=coalesce(ForwardingAddress,ForwardingSmtpAddress)
| search ForwardTo!=\"\"
| rename user_id as user
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(ForwardTo) as ForwardTo by signature dest user src vendor_account vendor_product object ObjectId
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_mailbox_email_forwarding_enabled_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Mailbox Folder Read Permission Assigned
id: 1435475e-2128-4417-a34f-59770733b0d5
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
@@ -14,12 +14,12 @@ description: The following analytic identifies instances where read permissions
and potential information leakage. If confirmed malicious, an attacker could gain
unauthorized access to sensitive emails, leading to data breaches and compromising
the confidentiality of organizational communications.
search: "`o365_management_activity` Workload=Exchange (Operation=ModifyFolderPermissions
OR Operation=AddFolderPermissions) Workload=Exchange object!=Calendar object!=Contacts
object!=PersonMetadata | eval isReadRole=if(match('Item.ParentFolder.MemberRights',
\"(ReadAny)\"), \"true\", \"false\") | rename UserId as user | stats count earliest(_time)
as firstTime latest(_time) as lastTime by Operation, user, object, Item.ParentFolder.MemberUpn,
Item.ParentFolder.MemberRights | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=Exchange (Operation=ModifyFolderPermissions OR Operation=AddFolderPermissions) Workload=Exchange object!=Calendar object!=Contacts object!=PersonMetadata
| eval isReadRole=if(match('Item.ParentFolder.MemberRights',\"(ReadAny)\"), \"true\", \"false\")
| rename UserId as user
| stats count earliest(_time) as firstTime latest(_time) as lastTime by signature user object dest Item.ParentFolder.MemberUpn Item.ParentFolder.MemberRights src vendor_account vendor_product
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_mailbox_folder_read_permission_assigned_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Mailbox Folder Read Permission Granted
id: cd15c0a8-470e-4b12-9517-046e4927db30
version: 6
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
@@ -14,12 +14,15 @@ description: The following analytic identifies instances where read permissions
exposing sensitive email content. If confirmed malicious, an attacker could gain
unauthorized access to read email communications, leading to data breaches or information
leakage.
search: '`o365_management_activity` Workload=Exchange (Operation="Set-MailboxFolderPermission"
OR Operation="Add-MailboxFolderPermission" ) | eval isReadRole=if(match(AccessRights,
"^(ReadItems|Author|NonEditingAuthor|Owner|PublishingAuthor|Reviewer)$"), "true",
"false") | search isReadRole="true" | rename UserId as user | stats count earliest(_time)
as firstTime latest(_time) as lastTime by Operation, user, Identity, AccessRights
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_mailbox_folder_read_permission_granted_filter`'
search: '`o365_management_activity` Workload=Exchange (Operation="Set-MailboxFolderPermission" OR Operation="Add-MailboxFolderPermission" )
| eval isReadRole=if(match(AccessRights,"^(ReadItems|Author|NonEditingAuthor|Owner|PublishingAuthor|Reviewer)$"), "true", "false")
| search isReadRole="true"
| rename UserId as user
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product Identity AccessRights
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_mailbox_folder_read_permission_granted_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Mailbox folder permissions may be configured for legitimate
@@ -1,6 +1,6 @@
name: O365 Mailbox Inbox Folder Shared with All Users
id: 21421896-a692-4594-9888-5faeb8a53106
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -15,12 +15,15 @@ description: The following analytic detects instances where the inbox folder of
emails. If confirmed malicious, this could lead to data breaches, exfiltration of
confidential information, and further compromise through spear-phishing or other
malicious activities based on the accessed email content.
search: "`o365_management_activity` Operation=ModifyFolderPermissions Workload=Exchange
object=Inbox Item.ParentFolder.MemberUpn=Everyone | eval isReadRole=if(match('Item.ParentFolder.MemberRights',
\"(ReadAny)\"), \"true\", \"false\") | search isReadRole = \"true\" | stats count
earliest(_time) as firstTime latest(_time) as lastTime by Operation, UserId, object,
MailboxOwnerUPN, Item.ParentFolder.MemberUpn, Item.ParentFolder.MemberRights | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_mailbox_inbox_folder_shared_with_all_users_filter`"
search: "`o365_management_activity` Operation=ModifyFolderPermissions Workload=Exchange object=Inbox Item.ParentFolder.MemberUpn=Everyone
| eval isReadRole=if(match('Item.ParentFolder.MemberRights',\"(ReadAny)\"), \"true\", \"false\")
| search isReadRole = \"true\"
| rename UserId as user
| fillnull
| stats count earliest(_time) as firstTime latest(_time) as lastTime by signature, user, dest, vendor_account, vendor_product, object, MailboxOwnerUPN, Item.ParentFolder.MemberUpn, Item.ParentFolder.MemberRights, src
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_mailbox_inbox_folder_shared_with_all_users_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Administrators might temporarily share a mailbox with all users
@@ -1,6 +1,6 @@
name: O365 Mailbox Read Access Granted to Application
id: 27ab61c5-f08a-438a-b4d3-325e666490b3
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -15,12 +15,17 @@ description: The following analytic identifies instances where the Mail.Read Gra
read all emails within a user's mailbox, which often contain sensitive or confidential
information. If confirmed malicious, this could lead to data exfiltration, spear-phishing
attacks, or further compromise based on the information gathered from the emails.
search: "`o365_management_activity` Operation=\"Update application.\" | eval json_data=mvindex('ModifiedProperties{}.NewValue',
0) | eval json_data=replace(json_data, \"^\\[\\s*\", \"\") | eval json_data=replace(json_data,
\"\\s*\\]$\", \"\") | spath input=json_data path=RequiredAppPermissions{}.EntitlementId
output=EntitlementIds | eval match_found=mvfind(EntitlementIds, \"810c84a8-4a9e-49e6-bf7d-12d183f40d01\"\
) | where isnotnull(match_found) | stats max(_time) as lastTime values(EntitlementIds)
as EntitlementIds by Operation, user, object | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Operation=\"Update application.\"
| eval json_data=mvindex('ModifiedProperties{}.NewValue',0)
| eval json_data=replace(json_data,\"^\\[\\s*\",\"\")
| eval json_data=replace(json_data,\"\\s*\\]$\",\"\")
| spath input=json_data path=RequiredAppPermissions{}.EntitlementId output=EntitlementIds
| eval match_found=mvfind(EntitlementIds, \"810c84a8-4a9e-49e6-bf7d-12d183f40d01\")
| where isnotnull(match_found)
| fillnull
| stats count earliest(_time) as firstTime max(_time) as lastTime values(EntitlementIds) as EntitlementIds by signature, user, dest, vendor_account, vendor_product, object, src
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_mailbox_read_access_granted_to_application_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Multi-Source Failed Authentications Spike
id: ea4e2c41-dbfb-4f5f-a7b6-9ac1b7f104aa
version: 6
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -15,12 +15,15 @@ description: The following analytic identifies a spike in failed authentication
If confirmed malicious, this activity could lead to unauthorized access, data breaches,
privilege escalation, and lateral movement within the organization. Early detection
is crucial to prevent account takeovers and mitigate subsequent threats.
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed
ErrorNumber=50126 | bucket span=5m _time | eval uniqueIPUserCombo = src_ip . "-"
. user | stats dc(uniqueIPUserCombo) as uniqueIpUserCombinations, dc(user) as uniqueUsers,
dc(src_ip) as uniqueIPs, values(user) as user, values(src_ip) as ips, values(user_agent)
as user_agents by _time | where uniqueIpUserCombinations > 20 AND uniqueUsers >
20 AND uniqueIPs > 20 | `o365_multi_source_failed_authentications_spike_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed ErrorNumber=50126
| bucket span=5m _time
| eval uniqueIPUserCombo = src_ip . "-" . user
| fillnull
| stats earliest(_time) as firstTime max(_time) as lastTime dc(uniqueIPUserCombo) as uniqueIpUserCombinations, dc(user) as uniqueUsers, dc(src_ip) as uniqueIPs, values(user) as user, values(src_ip) as ips, values(user_agent) as user_agents values(signature) as signature values(src) as src values(dest) as dest by _time vendor_account vendor_product
| where uniqueIpUserCombinations > 20 AND uniqueUsers > 20 AND uniqueIPs > 20
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_multi_source_failed_authentications_spike_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. The thresholds set within the analytic (such
as unique IPs, unique users, etc.) are initial guidelines and should be customized
@@ -1,6 +1,6 @@
name: O365 Multiple AppIDs and UserAgents Authentication Spike
id: 66adc486-224d-45c1-8e4d-9e7eeaba988f
version: 5
version: 6
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -17,11 +17,11 @@ description: The following analytic identifies unusual authentication activity i
it suggests a compromised account, potentially leading to unauthorized access, privilege
escalation, and data exfiltration. Early detection is crucial to prevent further
exploitation.
search: '`o365_management_activity` Workload=AzureActiveDirectory (Operation=UserLoggedIn
OR Operation=UserLoginFailed) | bucket span=5m _time | stats dc(_raw) as failed_attempts
dc(ApplicationId) as unique_app_ids dc(UserAgent) as unique_user_agents values(ApplicationId)
values(OS) by _time user src_ip | where failed_attempts > 5 and unique_user_agents
> 5 and unique_app_ids > 2 | `o365_multiple_appids_and_useragents_authentication_spike_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory (Operation=UserLoggedIn OR Operation=UserLoginFailed)
| bucket span=5m _time
| stats dc(_raw) as failed_attempts dc(ApplicationId) as unique_app_ids dc(UserAgent) as unique_user_agents values(ApplicationId) values(OS) values(signature) as signature by _time user src vendor_account vendor_product dest
| where failed_attempts > 5 and unique_user_agents > 5 and unique_app_ids > 2
| `o365_multiple_appids_and_useragents_authentication_spike_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Rapid authentication from the same user using more than 5 different
@@ -54,7 +54,7 @@ rba:
type: user
score: 48
threat_objects:
- field: src_ip
- field: src
type: ip_address
tags:
analytic_story:
@@ -1,6 +1,6 @@
name: O365 Multiple Failed MFA Requests For User
id: fd22124e-dbac-4744-a8ce-be10d8ec3e26
version: 5
version: 6
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -16,10 +16,11 @@ description: The following analytic identifies potential "MFA fatigue" attacks t
requests. If confirmed malicious, this could lead to data breaches, unauthorized
data access, or further compromise within the O365 environment. Immediate investigation
is crucial.
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed
ResultStatus=Success ErrorNumber=500121 | bucket span=10m _time | stats dc(_raw)
as mfa_prompts values(LogonError) as LogonError values(signature) as signature by
user, _time | where mfa_prompts > 9 | `o365_multiple_failed_mfa_requests_for_user_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed ResultStatus=Success ErrorNumber=500121
| bucket span=10m _time
| stats dc(_raw) as mfa_prompts values(LogonError) as LogonError values(signature) as signature values(action) as action values(src) as src by user _time vendor_account vendor_product dest
| where mfa_prompts > 9
| `o365_multiple_failed_mfa_requests_for_user_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Multiple Failed MFA requests may also be a sign of authentication
@@ -1,6 +1,6 @@
name: O365 Multiple Mailboxes Accessed via API
id: 7cd853e9-d370-412f-965d-a2bcff2a2908
version: 5
version: 6
date: '2024-11-14'
author: Mauricio Velazco, Splunk
data_source:
@@ -16,12 +16,14 @@ description: The following analytic detects when a high number of Office 365 Exc
information, leading to data breaches and further exploitation of compromised accounts.
The threshold is set to flag over five unique mailboxes accessed within 10 minutes,
but should be tailored to your environment.
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed
AppId=* ClientAppId=* | bucket span=10m _time | eval matchRegex=if(match(ClientInfoString,
"^Client=WebServices;ExchangeWebServices"), 1, 0) | search (AppId="00000003-0000-0000-c000-000000000000"
OR matchRegex=1) | stats values(ClientIPAddress) as src_ip dc(user) as unique_mailboxes
values(user) as user by _time ClientAppId ClientInfoString | where unique_mailboxes
> 5 | `o365_multiple_mailboxes_accessed_via_api_filter`'
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed AppId=* ClientAppId=*
| bucket span=10m _time
| eval matchRegex=if(match(ClientInfoString,"^Client=WebServices;ExchangeWebServices"), 1, 0)
| search (AppId="00000003-0000-0000-c000-000000000000" OR matchRegex=1)
| fillnull
| stats values(ClientIPAddress) as src dc(user) as unique_mailboxes values(user) as user by _time ClientAppId ClientInfoString vendor_account vendor_product dest signature
| where unique_mailboxes > 5
| `o365_multiple_mailboxes_accessed_via_api_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Legitimate applications may access multiple mailboxes via an
@@ -1,6 +1,6 @@
name: O365 Multiple OS Vendors Authenticating From User
id: 3451e58a-9457-4985-a600-b616b0cbfda1
version: 1
version: 2
date: '2024-12-19'
author: Steven Dick
status: production
@@ -9,14 +9,15 @@ description: The following analytic identifies when multiple operating systems a
data_source:
- Office 365 Universal Audit Log
search: |-
`o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn)
| eval -time = _time
| bin _time span=15m
| stats values(Operation) as signature, values(ErrorNumber) as signature_id, values(OS) as os_name, dc(OS) as os_count, count, min(-time) as firstTime, max(-time) as lastTime by ClientIP, UserId, _time
| where os_count >= 4
| eval src = ClientIP, user = UserId
`o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn)
| eval -time = _time
| bin _time span=15m
| fillnull
| stats values(Operation) as signature, values(ErrorNumber) as signature_id, values(OS) as os_name, dc(OS) as os_count, count, min(-time) as firstTime, max(-time) as lastTime by ClientIP, UserId, _time, dest, vendor_account, vendor_product
| where os_count >= 4
| eval src = ClientIP, user = UserId
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(lastTime)`
| `o365_multiple_os_vendors_authenticating_from_user_filter`
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds set within the analytic (such as unique OS) are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment.
known_false_positives: IP or users where the usage of multiple Operating systems is expected, filter accordingly.
@@ -1,6 +1,6 @@
name: O365 Multiple Service Principals Created by SP
id: ef4c3f20-d1ad-4ad1-a3f4-d5f391c005fe
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
data_source:
@@ -15,12 +15,18 @@ description: The following analytic identifies instances where a single service
attempting to expand control or access within the network. If confirmed malicious,
this could lead to unauthorized access and potential lateral movement within the
environment, posing a significant security risk.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add
service principal.\" | bucket span=10m _time | eval len=mvcount('Actor{}.ID') |
eval userType = mvindex('Actor{}.ID',len-1) | search userType = \"ServicePrincipal\"\
\ | eval displayName = object | stats count earliest(_time) as firstTime latest(_time)
as lastTime values(displayName) as displayName dc(displayName) as unique_apps by
src_user | where unique_apps > 3 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add service principal.\"
| bucket span=10m _time
| eval len=mvcount('Actor{}.ID')
| eval userType = mvindex('Actor{}.ID',len-1)
| search userType = \"ServicePrincipal\"
| eval displayName = object
| fillnull
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(displayName) as displayName dc(displayName) as unique_apps values(user) as user values(src) as src
by src_user vendor_account vendor_product dest signature
| where unique_apps > 3
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_multiple_service_principals_created_by_sp_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Multiple Service Principals Created by User
id: a34e65d0-54de-4b02-9db8-5a04522067f6
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
data_source:
@@ -15,12 +15,17 @@ description: The following analytic identifies instances where a single user cre
potentially leading to broader network infiltration or privilege escalation. If
confirmed malicious, this behavior could allow attackers to gain persistent access,
escalate privileges, or exfiltrate sensitive information.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add
service principal.\" | bucket span=10m _time | eval len=mvcount('Actor{}.ID') |
eval userType = mvindex('Actor{}.ID',len-1) | search userType = \"User\" | eval
displayName = object | stats count earliest(_time) as firstTime latest(_time) as
lastTime values(displayName) as displayName dc(displayName) as unique_apps by src_user
| where unique_apps > 3 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add service principal.\"
| bucket span=10m _time
| eval len=mvcount('Actor{}.ID')
| eval userType = mvindex('Actor{}.ID',len-1)
| search userType = \"User\"
| eval displayName = object
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(displayName) as displayName dc(displayName) as unique_apps values(user) as user values(src) as src
by src_user vendor_account vendor_product dest signature
| where unique_apps > 3
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_multiple_service_principals_created_by_user_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Multiple Users Failing To Authenticate From Ip
id: 8d486e2e-3235-4cfe-ac35-0d042e24ecb4
version: 7
version: 8
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -16,10 +16,12 @@ description: The following analytic identifies instances where more than 10 uniq
multiple accounts, potentially leading to unauthorized access. Immediate action
is required to block or monitor the suspicious IP and notify affected users to enhance
their security measures.
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed
ErrorNumber=50126 | bucket span=5m _time | stats dc(user) as unique_accounts values(user)
as user values(LogonError) as LogonError values(signature) as signature values(UserAgent)
as UserAgent by _time, src_ip | where unique_accounts > 10 | `o365_multiple_users_failing_to_authenticate_from_ip_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed ErrorNumber=50126
| bucket span=5m _time
| fillnull
| stats dc(user) as unique_accounts values(user) as user values(LogonError) as LogonError values(signature) as signature values(UserAgent) as user_agent values(dest) as dest by _time src vendor_account vendor_product
| where unique_accounts > 10
| `o365_multiple_users_failing_to_authenticate_from_ip_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: A source Ip failing to authenticate with multiple users in
@@ -44,13 +46,13 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: Source Ip $src_ip$ failed to authenticate with 20 users within 5 minutes.
message: Source Ip $src$ failed to authenticate with 20 users within 5 minutes.
risk_objects:
- field: user
type: user
score: 63
threat_objects:
- field: src_ip
- field: src
type: ip_address
tags:
analytic_story:
@@ -1,6 +1,6 @@
name: O365 New Email Forwarding Rule Created
id: 68469fd0-1315-44ba-b7e4-e92847bb76d6
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
@@ -14,13 +14,17 @@ description: The following analytic identifies the creation of new email forward
unauthorized access to sensitive information. If confirmed malicious, attackers
could intercept and redirect emails, potentially compromising confidential communications
and leading to data breaches.
search: "`o365_management_activity` (Operation=New-InboxRule OR Operation=set-InboxRule)
| eval match1=mvfind('Parameters{}.Name', \"ForwardTo\") | eval match2=mvfind('Parameters{}.Name',
\"ForwardAsAttachmentTo\") | eval match3=mvfind('Parameters{}.Name', \"RedirectTo\"\
) | where match1>= 0 OR match2>= 0 OR match3>= 0 | eval ForwardTo=coalesce(ForwardTo,
ForwardAsAttachmentTo, RedirectTo) | stats count min(_time) as firstTime max(_time)
as lastTime values(Name) as Name by user Operation ForwardTo | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_new_email_forwarding_rule_created_filter`"
search: "`o365_management_activity` (Operation=New-InboxRule OR Operation=set-InboxRule)
| eval match1=mvfind('Parameters{}.Name', \"ForwardTo\")
| eval match2=mvfind('Parameters{}.Name', \"ForwardAsAttachmentTo\")
| eval match3=mvfind('Parameters{}.Name', \"RedirectTo\")
| where match1>= 0 OR match2>= 0 OR match3>= 0
| eval ForwardTo=coalesce(ForwardTo, ForwardAsAttachmentTo, RedirectTo)
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime values(Name) as Name by signature dest user src vendor_account vendor_product ForwardTo
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_new_email_forwarding_rule_created_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Users may create email forwarding rules for legitimate purposes.
@@ -1,6 +1,6 @@
name: O365 New Email Forwarding Rule Enabled
id: ac7c4d0a-06a3-4278-aa59-88a5e537f981
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
@@ -13,17 +13,23 @@ description: The following analytic identifies the creation of new email forward
This activity is significant as it may indicate unauthorized email redirection,
potentially leading to data exfiltration. If confirmed malicious, attackers could
intercept sensitive communications, leading to data breaches and information leakage.
search: "`o365_management_activity` Workload=Exchange Operation=UpdateInboxRules \
\ | eval match1=mvfind('OperationProperties{}.Value', \"ForwardToRecipientsAction\"\
) | eval match2=mvfind('OperationProperties{}.Value', \"ForwardAsAttachmentToRecipientsAction\"\
) | eval match3=mvfind('OperationProperties{}.Value', \"RedirectToRecipientsAction\"\
) | eval index = mvfind('OperationProperties{}.Name', \"ServerRule\") | where match1>=
0 OR match2>= 0 OR match3>= 0 | eval ServerRule = mvindex('OperationProperties{}.Value',
index-1) | spath input=ServerRule path=Actions{}.Recipients{}.Values{}.Value output=valueExtracted
| mvexpand valueExtracted | search valueExtracted=\"*@*.*\" | eval ForwardTo=if(match(valueExtracted,
\"^[^@]+@[^@]+\\\\.[^@]+$\"), valueExtracted, null) | dedup ForwardTo | where isnotnull(ForwardTo)
| stats count min(_time) as firstTime max(_time) as lastTime values(Name) as Name
by user Operation ForwardTo | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=Exchange Operation=UpdateInboxRules
| eval match1=mvfind('OperationProperties{}.Value', \"ForwardToRecipientsAction\")
| eval match2=mvfind('OperationProperties{}.Value', \"ForwardAsAttachmentToRecipientsAction\")
| eval match3=mvfind('OperationProperties{}.Value', \"RedirectToRecipientsAction\")
| eval index = mvfind('OperationProperties{}.Name', \"ServerRule\")
| where match1>=0 OR match2>= 0 OR match3>= 0
| eval ServerRule = mvindex('OperationProperties{}.Value',index-1)
| spath input=ServerRule path=Actions{}.Recipients{}.Values{}.Value output=valueExtracted
| mvexpand valueExtracted
| search valueExtracted=\"*@*.*\"
| eval ForwardTo=if(match(valueExtracted,\"^[^@]+@[^@]+\\\\.[^@]+$\"), valueExtracted, null)
| dedup ForwardTo
| where isnotnull(ForwardTo)
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime values(Name) as Name by signature dest user src vendor_account vendor_product ForwardTo
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_new_email_forwarding_rule_enabled_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 New Federated Domain Added
id: e155876a-6048-11eb-ae93-0242ac130002
version: 7
version: 8
date: '2025-02-10'
author: Rod Soto, Mauricio Velazco Splunk
status: production
@@ -15,10 +15,13 @@ description: The following analytic identifies the addition of a new federated d
to review the details of the added domain and any concurrent suspicious activities.
data_source:
- O365
search: '`o365_management_activity` Operation IN ("*add*", "*new*") AND Operation="*domain*"
| stats count values(ModifiedProperties{}.NewValue) as new_value by user user_agent
authentication_service action Workload Operation | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_new_federated_domain_added_filter`'
search: '`o365_management_activity` Operation IN ("*add*", "*new*") AND Operation="*domain*"
| eval src="NA"
| fillnull
| stats count values(ModifiedProperties{}.NewValue) as new_value by user user_agent authentication_service signature Workload src vendor_account vendor_product dest
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_new_federated_domain_added_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity.
known_false_positives: The creation of a new Federated domain is not necessarily malicious,
@@ -1,6 +1,6 @@
name: O365 New Forwarding Mailflow Rule Created
id: 289ed0a1-4c78-4a43-9321-44ea2e089c14
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
data_source: []
@@ -13,14 +13,19 @@ description: The following analytic detects the creation of new mail flow rules
This activity is significant as it can indicate potential data exfiltration or unauthorized
access to sensitive information. If confirmed malicious, attackers could intercept
or redirect email communications, leading to data breaches or information leakage.
search: "`o365_management_activity` Workload=Exchange Operation=\"New-TransportRule\"\
\ | eval match1=mvfind('Parameters{}.Name', \"BlindCopyTo\") | eval match2=mvfind('Parameters{}.Name',
\"CopyTo\") | eval match3=mvfind('Parameters{}.Name', \"RedirectMessageTo\") | where
match1>= 0 OR match2>= 0 OR match3>=0 | eval ForwardTo=coalesce(BlindCopyTo, CopyTo,
RedirectMessageTo) | search ForwardTo!=\"\" | rename UserId as user | stats count
earliest(_time) as firstTime latest(_time) as lastTime by Operation, user, Name,
ForwardTo | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`\
\ | `o365_new_forwarding_mailflow_rule_created_filter`"
search: "`o365_management_activity` Workload=Exchange Operation=\"New-TransportRule\"
| eval match1=mvfind('Parameters{}.Name',\"BlindCopyTo\")
| eval match2=mvfind('Parameters{}.Name',\"CopyTo\")
| eval match3=mvfind('Parameters{}.Name', \"RedirectMessageTo\")
| where match1>= 0 OR match2>= 0 OR match3>=0
| eval ForwardTo=coalesce(BlindCopyTo, CopyTo, RedirectMessageTo)
| search ForwardTo!=\"\"
| rename UserId as user
| fillnull
| stats count earliest(_time) as firstTime latest(_time) as lastTime by user, Name, ForwardTo, vendor_account, vendor_product, dest, signature
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_new_forwarding_mailflow_rule_created_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Forwarding mail flow rules may be created for legitimate reasons,
@@ -1,6 +1,6 @@
name: O365 New MFA Method Registered
id: 4e12db1f-f7c7-486d-8152-a221cad6ac2b
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -14,16 +14,21 @@ description: The following analytic detects the registration of a new Multi-Fact
account. If confirmed malicious, the attacker could bypass existing security measures,
solidify their access, and potentially escalate privileges or access sensitive data.
Immediate verification and remediation are required to secure the affected account.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
user.\" | eval propertyName = mvindex('ModifiedProperties{}.Name', 0) | search
propertyName = StrongAuthenticationMethod | eval oldvalue = mvindex('ModifiedProperties{}.OldValue',0)
| eval newvalue = mvindex('ModifiedProperties{}.NewValue',0) | rex field=newvalue
max_match=0 \"(?i)(?<new_method_type>\\\"MethodType\\\")\" | rex field=oldvalue
max_match=0 \"(?i)(?<old_method_type>\\\"MethodType\\\")\" | eval count_new_method_type
= coalesce(mvcount(new_method_type), 0) | eval count_old_method_type = coalesce(mvcount(old_method_type),
0) | where count_new_method_type > count_old_method_type | stats earliest(_time)
as firstTime latest(_time) as lastTime values(propertyName) by user newvalue oldvalue
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_new_mfa_method_registered_filter`"
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update user.\"
| eval propertyName = mvindex('ModifiedProperties{}.Name', 0)
| search propertyName = StrongAuthenticationMethod
| eval oldvalue = mvindex('ModifiedProperties{}.OldValue',0)
| eval newvalue = mvindex('ModifiedProperties{}.NewValue',0)
| rex field=newvalue max_match=0 \"(?i)(?<new_method_type>\\\"MethodType\\\")\"
| rex field=oldvalue max_match=0 \"(?i)(?<old_method_type>\\\"MethodType\\\")\"
| eval count_new_method_type = coalesce(mvcount(new_method_type), 0)
| eval count_old_method_type = coalesce(mvcount(old_method_type), 0)
| where count_new_method_type > count_old_method_type
| fillnull
| stats earliest(_time) as firstTime latest(_time) as lastTime values(propertyName) by user newvalue oldvalue vendor_account vendor_product dest signature src
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_new_mfa_method_registered_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Users may register MFA methods legitimally, investigate and
@@ -1,6 +1,6 @@
name: O365 OAuth App Mailbox Access via EWS
id: e600cf1a-0bef-4426-b42e-00176d610a4d
version: 5
version: 6
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -15,11 +15,13 @@ description: The following analytic detects when emails are accessed in Office 3
emails through EWS is crucial for identifying potential abuse or unauthorized data
access. If confirmed malicious, this activity could lead to unauthorized email access,
data exfiltration, or further compromise of sensitive information.
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed
AppId=* ClientAppId=* | regex ClientInfoString="^Client=WebServices;ExchangeWebServices"
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(ClientIPAddress)
as src_ip by user ClientAppId OperationCount AppId ClientInfoString | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_oauth_app_mailbox_access_via_ews_filter`'
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed AppId=* ClientAppId=*
| regex ClientInfoString="^Client=WebServices;ExchangeWebServices"
| fillnull
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(ClientIPAddress) as src by user ClientAppId OperationCount AppId vendor_account vendor_product dest signature ClientInfoString
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_oauth_app_mailbox_access_via_ews_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: OAuth applications may access mailboxes for legitimate purposes,
@@ -1,6 +1,6 @@
name: O365 OAuth App Mailbox Access via Graph API
id: 9db0d5b0-4058-4cb7-baaf-77d8143539a2
version: 5
version: 6
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -13,11 +13,12 @@ description: The following analytic detects when emails are accessed in Office 3
on OAuth-authenticated applications. This activity is significant as unauthorized
access to emails can lead to data breaches and information theft. If confirmed malicious,
attackers could exfiltrate sensitive information, compromise user accounts, and
further infiltrate the organizations network.
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed
AppId=* AppId=00000003-0000-0000-c000-000000000000 | stats count earliest(_time)
as firstTime latest(_time) as lastTime values(ClientIPAddress) by user ClientAppId
OperationCount AppId | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
further infiltrate the organization's network.
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed AppId=* AppId=00000003-0000-0000-c000-000000000000
| fillnull
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(ClientIPAddress) as src by user ClientAppId OperationCount AppId vendor_account vendor_product dest signature
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_oauth_app_mailbox_access_via_graph_api_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Privileged Graph API Permission Assigned
id: 868f3131-d5e1-4bf1-af5b-9b0fbaaaedbb
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -15,14 +15,15 @@ description: The following analytic detects the assignment of critical Graph API
provide extensive control over Azure AD settings, posing a high risk if misused.
If confirmed malicious, this could allow unauthorized modifications, leading to
potential data breaches or privilege escalation. Immediate investigation is crucial.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
application.\" | eval newvalue = mvindex('ModifiedProperties{}.NewValue',0) | spath
input=newvalue | search \"{}.RequiredAppPermissions{}.EntitlementId\"=\"1bfefb4e-e0b5-418b-a88f-73c46d2cc8e9\"\
\ OR \"{}.RequiredAppPermissions{}.EntitlementId\"=\"06b708a9-e830-4db3-a914-8e69da51d44f\"\
\ OR \"{}.RequiredAppPermissions{}.EntitlementId\"=\"9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8\"\
\ | eval Permissions = '{}.RequiredAppPermissions{}.EntitlementId' | stats count
earliest(_time) as firstTime latest(_time) as lastTime values(Permissions) by user,
object, user_agent, Operation | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update application.\"
| eval newvalue = mvindex('ModifiedProperties{}.NewValue',0)
| spath input=newvalue
| search \"{}.RequiredAppPermissions{}.EntitlementId\"=\"1bfefb4e-e0b5-418b-a88f-73c46d2cc8e9\" OR \"{}.RequiredAppPermissions{}.EntitlementId\"=\"06b708a9-e830-4db3-a914-8e69da51d44f\" OR \"{}.RequiredAppPermissions{}.EntitlementId\"=\"9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8\"
| eval Permissions = '{}.RequiredAppPermissions{}.EntitlementId'
| fillnull
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(Permissions) by user src object user_agent signature vendor_account vendor_product dest
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_privileged_graph_api_permission_assigned_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Privileged Role Assigned
id: db435700-4ddc-4c23-892e-49e7525d7d39
version: 5
version: 6
date: '2025-02-10'
author: Steven Dick
status: production
@@ -11,18 +11,15 @@ description: The following analytic identifies the assignment of sensitive and p
AD environment. This detection leverages the O365 Universal Audit Log data source.
data_source:
- Office 365 Universal Audit Log
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"\
Add member to role.\",\"Add eligible member to role.\") | eval user = ObjectId,
src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name
= mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"\
Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"\
Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category =
mvindex('Target{}.ID',2) | stats count, min(_time) as firstTime, max(_time) as lastTime
by src_user, user, category, result, object_name, object_id, signature | lookup
privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole
| search isprvilegedadrole=\"TRUE\" category=\"User\" | `security_content_ctime(firstTime)`\
\ | `security_content_ctime(lastTime)` | `o365_privileged_role_assigned_filter`"
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add member to role.\",\"Add eligible member to role.\")
| eval user = ObjectId, src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category = mvindex('Target{}.ID',2)
| fillnull
| stats count, min(_time) as firstTime, max(_time) as lastTime by src_user, src, user, category, result, object_name, object_id, signature, vendor_account, vendor_product, dest
| lookup privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole
| search isprvilegedadrole=\"TRUE\" category=\"User\"
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_privileged_role_assigned_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Administrators will legitimately assign the privileged roles
@@ -1,6 +1,6 @@
name: O365 Privileged Role Assigned To Service Principal
id: 80f3fc1b-705f-4080-bf08-f61bf013b900
version: 5
version: 6
date: '2025-02-10'
author: Steven Dick
status: production
@@ -15,18 +15,15 @@ description: The following analytic detects potential privilege escalation threa
source.
data_source:
- Office 365 Universal Audit Log
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"\
Add member to role.\",\"Add eligible member to role.\") | eval user = ObjectId,
src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name
= mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"\
Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"\
Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category =
mvindex('Target{}.ID',2) | stats count, min(_time) as firstTime, max(_time) as lastTime
by src_user, user, category, result, object_name, object_id, signature | lookup
privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole
| search isprvilegedadrole=\"TRUE\" category!=\"User\" | `security_content_ctime(firstTime)`\
\ | `security_content_ctime(lastTime)` | `o365_privileged_role_assigned_to_service_principal_filter`"
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add member to role.\",\"Add eligible member to role.\")
| eval user = ObjectId, src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category = mvindex('Target{}.ID',2)
| fillnull
| stats count, min(_time) as firstTime, max(_time) as lastTime by src_user, src, user, category, result, object_name, object_id, signature,vendor_account, vendor_product, dest
| lookup privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole
| search isprvilegedadrole=\"TRUE\" category!=\"User\"
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_privileged_role_assigned_to_service_principal_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Administrators may legitimately assign the privileged roles
+14 -12
View File
@@ -1,6 +1,6 @@
name: O365 PST export alert
id: 5f694cc4-a678-4a60-9410-bffca1b647dc
version: 5
version: 6
date: '2024-11-14'
author: Rod Soto, Splunk
status: production
@@ -16,10 +16,12 @@ description: The following analytic detects instances where a user has initiated
Immediate investigation is required.
data_source:
- O365
search: '`o365_management_activity` Category=ThreatManagement Name="eDiscovery search
started or exported" | stats count earliest(_time) as firstTime latest(_time) as
lastTime by Source Severity AlertEntityId Operation Name |`security_content_ctime(firstTime)`
|`security_content_ctime(lastTime)` | `o365_pst_export_alert_filter`'
search: '`o365_management_activity` Category=ThreatManagement Name="eDiscovery search started or exported"
| fillnull
| stats count earliest(_time) as firstTime latest(_time) as lastTime by Source Severity AlertEntityId Name user src vendor_account vendor_product dest signature
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_pst_export_alert_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: PST export can be done for legitimate purposes but due to the
@@ -27,12 +29,12 @@ known_false_positives: PST export can be done for legitimate purposes but due to
references:
- https://attack.mitre.org/techniques/T1114/
drilldown_searches:
- name: View the detection results for - "$Source$"
search: '%original_detection_search% | search Source = "$Source$"'
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$Source$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$Source$")
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
@@ -41,10 +43,10 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $Source$ has exported a PST file from the search using this operation-
$Operation$ with a severity of $Severity$
message: User $user$ has exported a PST file from the search using this operation-
$signature$ with a severity of $Severity$
risk_objects:
- field: Source
- field: user
type: user
score: 48
threat_objects: []
+10 -12
View File
@@ -1,7 +1,7 @@
name: O365 Safe Links Detection
id: 711d9e8c-2cb0-45cf-8813-5f191ecb9b26
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -11,11 +11,12 @@ description: The following analytic detects when any Microsoft Safe Links alerti
data_source:
- Office 365 Universal Audit Log
search: '`o365_management_activity` Name="*a potentially malicious URL*" Operation=AlertEntityGenerated
| fromjson Data | stats count min(_time) as firstTime max(_time) as lastTime values(ObjectId)
as url values(od) as desc by AlertId,trc,Operation,Name,ot | rename Name as signature,
AlertId as signature_id, trc as user,ot as action | eval action = CASE(action ==
"Allowed", "allowed", action=="BlockPageOverride", "allowed", true(),"blocked")
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_safe_links_detection_filter`'
| fromjson Data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime
values(ObjectId) as url values(od) as desc by AlertId, trc, Name, ot, dest, vendor_account,
vendor_product, src | rename Name as signature, AlertId as signature_id, trc as
user, ot as action | eval action = CASE(action == "Allowed", "allowed", action=="BlockPageOverride",
"allowed", true(),"blocked") | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `o365_safe_links_detection_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. The Safe Links capability must be configured
and is typically only available to E3/E5 level customers.
@@ -43,9 +44,7 @@ rba:
- field: user
type: user
score: 40
threat_objects:
- field: url
type: url
threat_objects: []
tags:
analytic_story:
- Office 365 Account Takeover
@@ -61,7 +60,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,6 +1,6 @@
name: O365 Security And Compliance Alert Triggered
id: 5b367cdd-8dfc-49ac-a9b7-6406cf27f33e
version: 6
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source: []
@@ -15,14 +15,19 @@ description: The following analytic identifies alerts triggered by the Office 36
If confirmed malicious, these alerts could indicate attempts to breach security
policies, leading to unauthorized access, data exfiltration, or other malicious
activities.
search: '`o365_management_activity` Workload=SecurityComplianceCenter Category=ThreatManagement
Operation=AlertTriggered | spath input=Data path=f3u output=user | spath input=Data
path=op output=operation | spath input=_raw path=wl | spath input=Data path=rid
output=rule_id | spath input=Data path=ad output=alert_description | spath input=Data
path=lon output=operation_name | spath input=Data path=an output=alert_name | spath
input=Data path=sev output=severity | stats count earliest(_time) as firstTime
latest(_time) as lastTime by user, Name, operation, rule_id, alert_description,
alert_name, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
search: '`o365_management_activity` Workload=SecurityComplianceCenter Category=ThreatManagement Operation=AlertTriggered
| spath input=Data path=f3u output=user
| spath input=Data path=op output=operation
| spath input=_raw path=wl
| spath input=Data path=rid output=rule_id
| spath input=Data path=ad output=alert_description
| spath input=Data path=lon output=operation_name
| spath input=Data path=an output=alert_name
| spath input=Data path=sev output=severity
| fillnull
| stats count earliest(_time) as firstTime latest(_time) as lastTime by user, Name, rule_id, alert_description, alert_name, severity, dest, src, vendor_account, vendor_product, signature
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_security_and_compliance_alert_triggered_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 Service Principal New Client Credentials
id: a1b229e9-d962-4222-8c62-905a8a010453
version: 7
version: 8
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -15,10 +15,12 @@ description: The following analytic detects the addition of new credentials for
operations under the application's identity.
data_source:
- O365
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Update
application*Certificates and secrets management " | stats earliest(_time) as firstTime
latest(_time) as lastTime by user ModifiedProperties{}.NewValue object ObjectId
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_service_principal_new_client_credentials_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Update application*Certificates and secrets management "
| fillnull
| stats earliest(_time) as firstTime latest(_time) as lastTime by user ModifiedProperties{}.NewValue object ObjectId dest signature src vendor_account vendor_product
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_service_principal_new_client_credentials_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Service Principal client credential modifications may be part
@@ -1,28 +1,25 @@
name: O365 Service Principal Privilege Escalation
id: b686d0bd-cca7-44ca-ae07-87f6465131d9
version: 2
version: 3
date: '2025-02-10'
author: Dean Luxton
data_source:
- O365 Add app role assignment grant to user.
type: TTP
status: production
description: This detection identifies when an Azure Service Principal elevates privileges
by adding themself to a new app role assignment.
search: >-
`o365_management_activity` Operation="Add app role assignment to service principal."
"Actor{}.ID"=ServicePrincipal ResultStatus=Success
| spath path=ModifiedProperties{} output=targetResources
| stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value"))))
as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName"))))
as targetServicePrincipal values(object) as targetAppContext values(user_agent)
as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by
Operation InterSystemsId tenant_id
| spath input=appRole path=NewValue output=appRole
| spath input=targetServicePrincipal path=NewValue output=targetServicePrincipal
| where servicePrincipal=targetServicePrincipal
| table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext
user_agent tenant_id InterSystemsId
description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment.
search: >-
`o365_management_activity` Operation="Add app role assignment to service principal." "Actor{}.ID"=ServicePrincipal ResultStatus=Success
| spath path=ModifiedProperties{} output=targetResources
| eval src="NA"
| stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(object) as targetAppContext values(user_agent) as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by Operation InterSystemsId tenant_id user dest src vendor_account vendor_product signature
| spath input=appRole path=NewValue output=appRole
| spath input=targetServicePrincipal path=NewValue output=targetServicePrincipal
| where servicePrincipal=targetServicePrincipal
| fillnull
| stats earliest(_time) as firstTime latest(_time) as lastTime by servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenant_id InterSystemsId user dest src vendor_account vendor_product signature
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_service_principal_privilege_escalation_filter`
how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to
ingest EntraID audit logs via the 365 API. See references for links for further
@@ -1,7 +1,7 @@
name: O365 SharePoint Allowed Domains Policy Changed
id: b0cc6fa8-39b1-49ac-a4fe-f2f2a668e06c
version: 6
date: '2024-11-14'
version: 7
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -13,19 +13,19 @@ description: The following analytic identifies when the allowed domain settings
access.
data_source:
- Office 365 Universal Audit Log
search: "`o365_management_activity` Workload=SharePoint Operation=SharingPolicyChanged
\"ModifiedProperties{}.Name\"=AllowDomainList | eval signature_id = CorrelationId,
signature=Operation, src = ClientIP, user = UserId, object_name='ModifiedProperties{}.Name',
object_attrs_new = split(replace('ModifiedProperties{}.NewValue',\"\\.\\.\\.\",\"\
\"),\",\"), object_attrs_old = split(replace('ModifiedProperties{}.OldValue',\"\\\
.\\.\\.\",\"\"),\",\") | stats values(object_attrs_new) as object_attrs_new, values(object_attrs_old)
search: '`o365_management_activity` Workload=SharePoint Operation=SharingPolicyChanged
"ModifiedProperties{}.Name"=AllowDomainList | eval signature_id = CorrelationId,
signature=Operation, src = ClientIP, user = UserId, object_name=''ModifiedProperties{}.Name'',
object_attrs_new = split(replace(''ModifiedProperties{}.NewValue'',"\.\.\.",""),","),
object_attrs_old = split(replace(''ModifiedProperties{}.OldValue'',"\.\.\.",""),",")
| fillnull | stats values(object_attrs_new) as object_attrs_new, values(object_attrs_old)
as object_attrs_old, values(src) as src, count, min(_time) as firstTime, max(_time)
as lastTime by user,signature,signature_id,object_name | eval diff_add=mvmap(object_attrs_new,if(isnull(mvfind(object_attrs_old,object_attrs_new)),object_attrs_new,null))
as lastTime by user,signature,signature_id,object_name,dest,action,vendor_account,vendor_product
| eval diff_add=mvmap(object_attrs_new,if(isnull(mvfind(object_attrs_old,object_attrs_new)),object_attrs_new,null))
| eval diff_remove=mvmap(object_attrs_old,if(isnull(mvfind(object_attrs_new,object_attrs_old)),object_attrs_old,null))
| eval result = case(isnotnull(diff_add),\"Added \".mvjoin(diff_add,\",\"),isnotnull(diff_remove),\"\
Removed \".mvjoin(diff_remove,\",\")), action = case(isnotnull(diff_add),\"created\"\
,isnotnull(diff_remove),\"deleted\") | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `o365_sharepoint_allowed_domains_policy_changed_filter`"
| eval result = case(isnotnull(diff_add),"Added ".mvjoin(diff_add,","),isnotnull(diff_remove),"Removed
".mvjoin(diff_remove,",")), action = case(isnotnull(diff_add),"created",isnotnull(diff_remove),"deleted")
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_sharepoint_allowed_domains_policy_changed_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Business approved changes by known administrators.
@@ -66,7 +66,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,7 +1,7 @@
name: O365 SharePoint Malware Detection
id: 583c5de3-7709-44cb-abfc-0e828d301b59
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -12,11 +12,12 @@ description: The following analytic identifies when a malicious file is detected
Office 365 capabilities further enhance these detection and response functions.
data_source:
- Office 365 Universal Audit Log
search: '`o365_management_activity` Operation=FileMalwareDetected | stats values(Workload)
as category, values(SourceFileName) as file_name values(ObjectId) as file_path,
values(VirusInfo) as signature, count, min(_time) as firstTime, max(_time) as lastTime
by Id, UserId | rename Id as signature_id, UserId as user | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_sharepoint_malware_detection_filter`'
search: '`o365_management_activity` Operation=FileMalwareDetected | rename UserId
as user, Id as signature_id | stats values(Workload) as category, values(SourceFileName)
as file_name values(ObjectId) as file_path, values(VirusInfo) as signature, count,
min(_time) as firstTime, max(_time) as lastTime by signature_id, user, dest, src,
vendor_account, vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `o365_sharepoint_malware_detection_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: unknown
@@ -61,7 +62,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,6 +1,6 @@
name: O365 Tenant Wide Admin Consent Granted
id: 50eaabf8-5180-4e86-bfb2-011472c359fc
version: 5
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
@@ -15,12 +15,16 @@ description: The following analytic identifies instances where admin consent is
data. If confirmed malicious, an attacker could gain extensive and persistent access
to organizational data, leading to data exfiltration, espionage, further malicious
activities, and potential compliance violations.
search: "`o365_management_activity` Operation=\"Consent to application.\" | eval
new_field=mvindex('ModifiedProperties{}.NewValue', 4) | rex field=new_field \"ConsentType:
(?<ConsentType>[^\\,]+)\" | rex field=new_field \"Scope: (?<Scope>[^\\,]+)\" |
search ConsentType = \"AllPrincipals\" | stats count min(_time) as firstTime max(_time)
as lastTime by Operation, user, object, ObjectId, ConsentType, Scope | `security_content_ctime(firstTime)`\
\ | `security_content_ctime(lastTime)` | `o365_tenant_wide_admin_consent_granted_filter`"
search: "`o365_management_activity` Operation=\"Consent to application.\"
| eval new_field=mvindex('ModifiedProperties{}.NewValue', 4)
| rex field=new_field \"ConsentType: (?<ConsentType>[^\\,]+)\"
| rex field=new_field \"Scope: (?<Scope>[^\\,]+)\"
| search ConsentType = \"AllPrincipals\"
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by user, object, ObjectId, ConsentType, Scope, dest, vendor_account, vendor_product, signature, src
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `o365_tenant_wide_admin_consent_granted_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
known_false_positives: Legitimate applications may be granted tenant wide consent,
@@ -1,7 +1,7 @@
name: O365 Threat Intelligence Suspicious Email Delivered
id: 605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: Anomaly
@@ -21,8 +21,8 @@ search: '`o365_management_activity` Workload=ThreatIntelligence Operation=TIMail
values(ThreatsAndDetectionTech{}) as category, values(AttachmentData{}.FileName)
as file_name, values(AttachmentData{}.FileType) as file_type, values(AttachmentData{}.SHA256)
as file_hash values(DetectionMethod) as signature, min(_time) as firstTime max(_time)
as lastTime, count by src_user,sender | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `o365_threat_intelligence_suspicious_email_delivered_filter`'
as lastTime, count by src_user,sender,dest,vendor_account,vendor_product | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_threat_intelligence_suspicious_email_delivered_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. The threat intelligence workload is typically
only visible to E3/E5 level customers.
@@ -73,7 +73,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,7 +1,7 @@
name: O365 Threat Intelligence Suspicious File Detected
id: 00958c7b-35db-4e7a-ad13-31550a7a7c64
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: TTP
@@ -14,9 +14,10 @@ description: The following analytic identifies when a malicious file is detected
data_source:
- Office 365 Universal Audit Log
search: '`o365_management_activity` Workload=ThreatIntelligence Operation=AtpDetection
| stats values(DetectionMethod) as category values(FileData.FileName) as file_name
values(FileData.FilePath) as file_path values(FileData.FileSize) as file_size values(FileData.MalwareFamily)
as signature count, min(_time) as firstTime, max(_time) as lastTime by Id, UserId
| eval dest="NA" | eval src="NA" | stats values(DetectionMethod) as category values(FileData.FileName)
as file_name values(FileData.FilePath) as file_path values(FileData.FileSize) as
file_size values(FileData.MalwareFamily) as signature count, min(_time) as firstTime,
max(_time) as lastTime by Id, UserId, dest, src, vendor_account, vendor_product
| rename Id as signature_id, UserId as user | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_threat_intelligence_suspicious_file_detected_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
@@ -66,7 +67,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,6 +1,6 @@
name: O365 User Consent Blocked for Risky Application
id: 242e4d30-cb59-4051-b0cf-58895e218f40
version: 4
version: 5
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -16,11 +16,14 @@ description: The following analytic identifies instances where Office 365 has bl
the organization. If confirmed malicious, this activity suggests that O365's security
measures successfully prevented a harmful application from accessing organizational
data, warranting immediate investigation.
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent
to application.\" ResultStatus=Failure | eval permissions =mvindex('ModifiedProperties{}.NewValue',
4) | eval reason =mvindex('ModifiedProperties{}.NewValue', 5) | search reason =
\"Risky application detected\" | rex field=permissions \"Scope: (?<Scope>[^,]+)\"\
\ | stats max(_time) as lastTime by Operation, user, reason, object, Scope | `security_content_ctime(lastTime)`
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent to application.\" ResultStatus=Failure
| eval permissions =mvindex('ModifiedProperties{}.NewValue', 4)
| eval reason =mvindex('ModifiedProperties{}.NewValue', 5)
| search reason = \"Risky application detected\"
| rex field=permissions \"Scope: (?<Scope>[^,]+)\"
| fillnull
| stats max(_time) as lastTime by user, reason, object, Scope, dest, src, vendor_account, vendor_product, signature
| `security_content_ctime(lastTime)`
| `o365_user_consent_blocked_for_risky_application_filter`"
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events.
@@ -1,6 +1,6 @@
name: O365 User Consent Denied for OAuth Application
id: 2d8679ef-b075-46be-8059-c25116cb1072
version: 5
version: 6
date: '2024-11-14'
author: Mauricio Velazco, Splunk
status: production
@@ -16,9 +16,11 @@ description: The following analytic identifies instances where a user has denied
or unfamiliar applications. If confirmed malicious, it suggests an attempt by a
potentially harmful application to gain unauthorized access, which was proactively
blocked by the user.
search: '`o365_graph` status.errorCode=65004 | rename userPrincipalName as user |
rename ipAddress as src_ip | stats max(_time) as lastTime by user src_ip appDisplayName
status.failureReason | `security_content_ctime(lastTime)` | `o365_user_consent_denied_for_oauth_application_filter`'
search: '`o365_graph` status.errorCode=65004
| rename userPrincipalName as user
| rename ipAddress as src_ip
| stats min(_time) as firstTime max(_time) as lastTime by user src_ip appDisplayName status.failureReason
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_user_consent_denied_for_oauth_application_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 events.
known_false_positives: OAuth applications that require mail permissions may be legitimate,
@@ -1,7 +1,7 @@
name: O365 ZAP Activity Detection
id: 4df275fd-a0e5-4246-8b92-d3201edaef7a
version: 5
date: '2025-02-10'
version: 6
date: '2025-03-25'
author: Steven Dick
status: production
type: Anomaly
@@ -13,12 +13,13 @@ description: The following analytic detects when the Microsoft Zero-hour Automat
data_source:
- Office 365 Universal Audit Log
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AlertEntityGenerated
Name="*messages containing malicious*" | fromjson Data | stats count min(_time)
as firstTime max(_time) as lastTime values(zu) as url values(zfn) as file_name values(ms)
as subject values(ttr) as result values(tsd) as src_user by AlertId,trc,Operation,Name
| rename Name as signature, AlertId as signature_id, trc as user | eval action =
CASE(match(result,"Success"), "blocked", true(),"allowed"), url = split(url,";")
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_zap_activity_detection_filter`'
Name="*messages containing malicious*" | fromjson Data | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime values(zu) as url values(zfn) as
file_name values(ms) as subject values(ttr) as result values(tsd) as src_user by
AlertId,trc,signature,Name,dest,src,vendor_account,vendor_product | rename Name
as signature, AlertId as signature_id, trc as user | eval action = CASE(match(result,"Success"),
"blocked", true(),"allowed"), url = split(url,";") | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `o365_zap_activity_detection_filter`'
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
Office 365 management activity events. Some features of Zero-hour purge are only
offered within E3/E5 license level tenants, events may not be available otherwise.
@@ -68,7 +69,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
sourcetype: o365:management:activity
source: o365
@@ -1,7 +1,7 @@
name: Common Ransomware Extensions
id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec
version: '12'
date: '2025-03-03'
version: '13'
date: '2025-03-25'
author: David Dorsey, Michael Haag, Splunk, Steven Dick
status: production
type: TTP
@@ -1,7 +1,7 @@
name: Delete ShadowCopy With PowerShell
id: 5ee2bcd0-b2ff-11eb-bb34-acde48001122
version: 5
date: '2024-11-13'
version: 6
date: '2025-03-25'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -57,6 +57,7 @@ tags:
- Ransomware
- Revil Ransomware
- DarkGate Malware
- VanHelsing Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1490
@@ -1,7 +1,7 @@
name: Deleting Shadow Copies
id: b89919ed-ee5f-492c-b139-95dbb162039e
version: '11'
date: '2025-03-03'
version: '12'
date: '2025-03-25'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -81,6 +81,7 @@ tags:
- Windows Log Manipulation
- Compromised Windows Host
- Clop Ransomware
- VanHelsing Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1490
@@ -1,7 +1,7 @@
name: Detect Copy of ShadowCopy with Script Block Logging
id: 9251299c-ea5b-11eb-a8de-acde48001122
version: 6
date: '2025-02-10'
version: 7
date: '2025-03-25'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -56,6 +56,7 @@ rba:
tags:
analytic_story:
- Credential Dumping
- VanHelsing Ransomware
asset_type: Endpoint
cve:
- CVE-2021-36934
@@ -1,7 +1,7 @@
name: Detect PsExec With accepteula Flag
id: 27c3a83d-cada-47c6-9042-67baf19d2574
version: 10
date: '2025-02-10'
version: 11
date: '2025-03-25'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -81,6 +81,7 @@ tags:
- BlackByte Ransomware
- DarkGate Malware
- Rhysida Ransomware
- VanHelsing Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1021.002
@@ -1,7 +1,7 @@
name: Detect Renamed PSExec
id: 683e6196-b8e8-11eb-9a79-acde48001122
version: '12'
date: '2025-02-24'
version: '13'
date: '2025-03-25'
author: Michael Haag, Splunk, Alex Oberkircher, Github Community
status: production
type: Hunting
@@ -51,6 +51,7 @@ tags:
- Rhysida Ransomware
- Earth Estries
- SamSam Ransomware
- VanHelsing Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1569.002
@@ -1,7 +1,7 @@
name: Executable File Written in Administrative SMB Share
id: f63c34fe-a435-11eb-935a-acde48001122
version: 8
date: '2025-02-10'
version: 9
date: '2025-03-25'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -66,6 +66,7 @@ tags:
- Compromised Windows Host
- Hermetic Wiper
- Trickbot
- VanHelsing Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1021.002
@@ -1,7 +1,7 @@
name: Living Off The Land Detection
id: 1be30d80-3a39-4df9-9102-64a467b24abc
version: 5
date: '2024-11-13'
version: 6
date: '2025-03-26'
author: Michael Haag, Splunk
status: production
type: Correlation
@@ -70,6 +70,6 @@ tests:
- name: True Positive Test
attack_data:
- data:
https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1218/living_off_the_land/lolbinrisk.log
https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1218/living_off_the_land/lolbinrisk.log
source: lotl
sourcetype: stash
@@ -1,7 +1,7 @@
name: Resize ShadowStorage volume
id: bc760ca6-8336-11eb-bcbb-acde48001122
version: 5
date: '2024-12-10'
version: 6
date: '2025-03-25'
author: Teoderick Contreras
status: production
type: TTP
@@ -73,6 +73,7 @@ tags:
- Compromised Windows Host
- Clop Ransomware
- BlackByte Ransomware
- VanHelsing Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1490

Some files were not shown because too many files have changed in this diff Show More