Office 365
Microsoft Office 365 cloud productivity suite including Exchange Online, SharePoint Online, OneDrive for Business, and Azure Active Directory. Logs are captured via the Office 365 Management Activity API.
Azure-Active-Directory
No description available.
👑 Azure AD Role Assignment
Add Member to Role - Privilege Escalation
Captures Azure Active Directory role assignment operations where users are added to administrative roles. Global Administrator assignments are the highest risk as they grant complete control over the tenant. This event is critical for detecting privilege escalation attacks and unauthorized administrative access.
Exchange
No description available.
📮 Inbox Rule Created with External Forwarding
New-InboxRule - User-level Email Forwarding
Captures New-InboxRule operations where users create inbox rules to automatically forward emails to external addresses. This is a common technique for data exfiltration and persistence as it bypasses administrator-level mailbox forwarding controls and can be harder to detect.
📤 Mailbox External Forwarding Configuration
Set-Mailbox with ForwardingSmtpAddress - Data Exfiltration Risk
Captures Set-Mailbox operations that configure ForwardingSmtpAddress, enabling automatic forwarding of emails to external addresses. This is a critical security event as it's commonly used for data exfiltration and persistence.
🔑 Mailbox Permission Delegation
Add-MailboxPermission - Persistent Mailbox Access
Captures Add-MailboxPermission operations that grant mailbox access rights to other users. FullAccess permissions are particularly concerning as they provide complete mailbox access, survive password resets, and can enable long-term persistence for attackers.
Sharepoint
No description available.
🔗 SharePoint Anonymous Link Created
Public File Sharing - Data Exposure Risk
Captures SharePoint Online events where users create anonymous sharing links ('Anyone with the link') for files or folders. These links allow unauthenticated access to content, creating potential data exposure risks, especially for sensitive documents in Finance, HR, or Legal sites.