Skip to content

Commit 1878e5a

Browse files
authored
Merge pull request #962 from 0xC0FFEEEE/susmailrule
0xC0FFEEEE - O365 Suspicious Mailbox Rule Created
2 parents 25f6824 + 3c9f298 commit 1878e5a

File tree

2 files changed

+14
-0
lines changed

2 files changed

+14
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:d379909545e2d03fd0334e1c498f15189b999dd0722d032028ec0fc34567f075
3+
size 1440
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
author: 0xC0FFEEEE
2+
id: 54715c41-4283-44f7-a327-fbd230d83c60
3+
date: '2025-02-14'
4+
description: 'Detection of suspicious mailbox rule creation.'
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1564.008/o365/o365_suspicious_mailbox_rule.log
8+
sourcetypes:
9+
- o365:management:activity
10+
references:
11+
- https://attack.mitre.org/techniques/T1564/008/

0 commit comments

Comments
 (0)