Skip to content

Commit 130c6b9

Browse files
updated investigation header
1 parent bbc9eee commit 130c6b9

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/integrations/o365/initial_access_entra_id_portal_login_impossible_travel.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ license = "Elastic License v2"
2525
name = "M365 Identity Login from Impossible Travel Location"
2626
note = """## Triage and analysis
2727
28-
### Investigating M365 Identity Login from M365 Identity Login from Impossible Travel Location
28+
### Investigating M365 Identity Login from Impossible Travel Location
2929
3030
Microsoft 365's cloud-based services enable global access, but this can be exploited by adversaries logging in from disparate locations within short intervals, indicating potential account compromise. The detection rule identifies such anomalies by analyzing login events for rapid geographic shifts, flagging suspicious activity that may suggest unauthorized access attempts.
3131

0 commit comments

Comments
 (0)