detection-rules
detection-rules copied to clipboard
[New Rule] Microsoft 365 - Sharing Policy Change
Description
Identifies when a change was made to your organization's sharing policy.
Required Info
Target indexes
filebeat-*, logs-o365*
Platforms
Microsoft 365
Optional Info
Query
event.dataset:o365.audit and event.provider:(SharePoint or OneDrive) and event.category:web and
event.action:SharingPolicyChanged and event.outcome:success
New fields required in ECS/data sources for this rule?
Related issues or PRs
False Positives
MITRE
ATTACK TACTIC Credential Access, Persistence ATTACK TECHNIQUE Account Manipulation
References
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
I'm just leaving a comment for activity.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
Just keeping it open.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
This has been closed due to inactivity. If you feel this is an error, please re-open and include a justifying comment.