Skip to content

Commit d11917e

Browse files
committed
Update o365_concurrent_sessions_from_different_ips.yml
1 parent 168bf7e commit d11917e

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

detections/cloud/o365_concurrent_sessions_from_different_ips.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: O365 Concurrent Sessions From Different Ips
22
id: 58e034de-1f87-4812-9dc3-a4f68c7db930
3-
version: 7
4-
date: '2025-05-02'
3+
version: 8
4+
date: '2025-06-02'
55
author: Mauricio Velazco, Splunk
66
status: production
77
type: TTP
@@ -17,7 +17,8 @@ data_source:
1717
- O365 UserLoggedIn
1818
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoggedIn
1919
| fillnull
20-
| stats count min(_time) as firstTime max(_time) as lastTime values(src) as src by signature dest user vendor_account vendor_product
20+
| stats count min(_time) as firstTime max(_time) as lastTime values(src) as src
21+
by signature dest user vendor_account vendor_product SessionId
2122
| where mvcount(src) > 1
2223
| `security_content_ctime(firstTime)`
2324
| `security_content_ctime(lastTime)`

0 commit comments

Comments
 (0)