Skip to content

Commit ffc6443

Browse files
authored
Update o365_email_transport_rule_changed.yml
1 parent 4bd74d8 commit ffc6443

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

detections/cloud/o365_email_transport_rule_changed.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,8 @@ description: The following analytic identifies when a user with sufficient acces
99
data_source:
1010
- O365
1111
search: '`o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*TransportRule"
12-
| eval object_name = case('Parameters{}.Name'=="Name",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Name$")),true(),ObjectId), object_id = case('Parameters{}.Name'=="Identity",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Identity$")),true(),Id)
12+
| rename Parameters{}.* as Parameters_*
13+
| eval object_name = case(Parameters_Name=="Name",mvindex(Parameters_Value,mvfind(Parameters_Name,"^Name$")),true(),ObjectId), object_id = case(Parameters_Name=="Identity",mvindex(Parameters_Value,mvfind(Parameters_Name,"^Identity$")),true(),Id)
1314
| stats values(object_name) as object_name, min(_time) as firstTime, max(_time) as lastTime, count by object_id, UserId, Operation
1415
| rename UserId as user, Operation as signature
1516
| `security_content_ctime(firstTime)`

0 commit comments

Comments
 (0)