Azure Active Directory
1 TemplateMicrosoft's cloud-based identity and access management service providing single sign-on, multi-factor authentication, and identity protection
Available Data Sources:
Authentication
Azure Active Directory sign-in logs capturing user authentication events with detailed device, location, and security context
Defender for Identity
1 TemplateCloud-based security solution that identifies, detects, and investigates advanced threats, compromised identities, and malicious insider actions
Available Data Sources:
Security-Alerts
Microsoft Defender for Identity alert for pass-the-ticket attacks indicating lateral movement through stolen Kerberos tickets
Exchange Online
1 TemplateCloud-based email and calendaring service part of Microsoft 365
Available Data Sources:
Email-Security
Exchange Online audit log for new inbox rule creation events
Windows
1 TemplateMicrosoft Windows Operating System - comprehensive desktop and server platform
Available Data Sources:
System
CLOP Ransomware Service Installation - Known persistence mechanism used by CLOP ransomware family