File tree Expand file tree Collapse file tree 1 file changed +4
-3
lines changed Expand file tree Collapse file tree 1 file changed +4
-3
lines changed Original file line number Diff line number Diff line change 1
1
name : O365 Concurrent Sessions From Different Ips
2
2
id : 58e034de-1f87-4812-9dc3-a4f68c7db930
3
- version : 7
4
- date : ' 2025-05 -02'
3
+ version : 8
4
+ date : ' 2025-06 -02'
5
5
author : Mauricio Velazco, Splunk
6
6
status : production
7
7
type : TTP
@@ -17,7 +17,8 @@ data_source:
17
17
- O365 UserLoggedIn
18
18
search : ' `o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoggedIn
19
19
| fillnull
20
- | stats count min(_time) as firstTime max(_time) as lastTime values(src) as src by signature dest user vendor_account vendor_product
20
+ | stats count min(_time) as firstTime max(_time) as lastTime values(src) as src
21
+ by signature dest user vendor_account vendor_product SessionId
21
22
| where mvcount(src) > 1
22
23
| `security_content_ctime(firstTime)`
23
24
| `security_content_ctime(lastTime)`
You can’t perform that action at this time.
0 commit comments