Skip to content

Commit 101865e

Browse files
nterl0k0xC0FFEEEE
andauthored
Update detections/cloud/o365_email_new_inbox_rule_created.yml
Add IPv6 suggestion Co-authored-by: 0xC0FFEEEE <[email protected]>
1 parent c7f56ce commit 101865e

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

detections/cloud/o365_email_new_inbox_rule_created.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,8 @@ data_source:
1010
- Office 365 Universal Audit Log
1111
search: |-
1212
`o365_management_activity` Workload=Exchange AND (Operation=New-InboxRule OR Operation=Set-InboxRule) Parameters{}.Name IN (SoftDeleteMessage,DeleteMessage,ForwardTo,ForwardAsAttachmentTo,RedirectTo,MoveToFolder,CopyToFolder)
13-
| eval file_path = mvappend(MoveToFolder,CopyToFolder), recipient=mvappend(ForwardTo, ForwardAsAttachmentTo, RedirectTo), user = lower(UserId), signature = Operation, src = mvindex(split(ClientIP,":"),0), desc = Name, action = 'Parameters{}.Name'
13+
| eval file_path = mvappend(MoveToFolder,CopyToFolder), recipient=mvappend(ForwardTo, ForwardAsAttachmentTo, RedirectTo), user = lower(UserId), signature = Operation, src = if(match(ClientIP, "^\["), ltrim(mvindex(split(ClientIP, "]:"), 0), "["), mvindex(split(ClientIP,":"),0)), desc = Name, action = 'Parameters{}.Name'
14+
1415
| stats values(action) as action, values(src) as src, values(recipient) as recipient, values(file_path) as file_path, count, min(_time) as firstTime, max(_time) as lastTime by user, signature, desc
1516
| `security_content_ctime(firstTime)`
1617
| `security_content_ctime(lastTime)`

0 commit comments

Comments
 (0)