Skip to content

Commit 8a0692d

Browse files
authored
add ActionType to behaviors table behaviors.md
1 parent f6b2bb7 commit 8a0692d

File tree

1 file changed

+16
-16
lines changed

1 file changed

+16
-16
lines changed

CloudAppSecurityDocs/behaviors.md

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -26,22 +26,22 @@ While behaviors might be related to security scenarios, they're not necessarily
2626

2727
Behaviors currently support low-fidelity, Defender for Cloud Apps detections, that may not meet the standard for alerts but are still useful in providing context during an investigation. Currently supported detections include:
2828

29-
|Alert name |Policy name |
30-
|---------|---------|
31-
|**Activity from infrequent country** |Activity from infrequent country/region  |
32-
|**Impossible travel activity** |Impossible travel |
33-
|**Mass delete** |Unusual file deletion activity (by user) |
34-
|**Mass download** |Unusual file download (by user) |
35-
|**Mass share** |Unusual file share activity (by user) |
36-
|**Multiple delete VM activities** |Multiple delete VM activities |
37-
|**Multiple failed login attempts** |Multiple failed sign-in attempts |
38-
|**Multiple Power BI report sharing activities** |Multiple Power BI report sharing activities |
39-
|**Multiple VM creation activities** |Multiple VM creation activities |
40-
|**Suspicious administrative activity** |Unusual administrative activity (by user) |
41-
|**Suspicious impersonated activity** |Unusual impersonated activity (by user) |
42-
|**Suspicious OAuth app file download activities** |Suspicious OAuth app file download activities |
43-
|**Suspicious Power BI report sharing** |Suspicious Power BI report sharing  |
44-
|**Unusual addition of credentials to an OAuth app** |Unusual addition of credentials to an OAuth app |
29+
|Alert name |Policy name |ActionType (Hunting)|
30+
|---------|---------|---------|
31+
|**Activity from infrequent country** |Activity from infrequent country/region  |ActivityFromInfrequentCountry|
32+
|**Impossible travel activity** |Impossible travel |ImpossibleTravelActivity|
33+
|**Mass delete** |Unusual file deletion activity (by user) |MassDelete|
34+
|**Mass download** |Unusual file download (by user) |MassDownload|
35+
|**Mass share** |Unusual file share activity (by user) |MassShare|
36+
|**Multiple delete VM activities** |Multiple delete VM activities |MultipleDeleteVmActivities|
37+
|**Multiple failed login attempts** |Multiple failed sign-in attempts |MultipleFailedLoginAttempts|
38+
|**Multiple Power BI report sharing activities** |Multiple Power BI report sharing activities |MultiplePowerBiReportSharingActivities|
39+
|**Multiple VM creation activities** |Multiple VM creation activities |MultipleVmCreationActivities|
40+
|**Suspicious administrative activity** |Unusual administrative activity (by user) |SuspiciousAdministrativeActivity|
41+
|**Suspicious impersonated activity** |Unusual impersonated activity (by user) |SuspiciousImpersonatedActivity|
42+
|**Suspicious OAuth app file download activities** |Suspicious OAuth app file download activities |SuspiciousOauthAppFileDownloadActivities|
43+
|**Suspicious Power BI report sharing** |Suspicious Power BI report sharing  |SuspiciousPowerBiReportSharing|
44+
|**Unusual addition of credentials to an OAuth app** |Unusual addition of credentials to an OAuth app |UnusualAdditionOfCredentialsToAnOauthApp|
4545

4646

4747
## Defender for Cloud Apps' transition from alerts to behaviors

0 commit comments

Comments
 (0)