Vendor: Microsoft Product: Office 365 Rules Models MITRE TTPs Event Types Parsers 716 154 118 20 20 Use-Case Event Types/Parsers MITRE TTP Content Abnormal Authentication & Access account-disabled ↳logrhythm-0365-app-login ↳json-o365-app-login app-activity ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳o365-activity ↳cef-o365-app-activity-3 ↳json-o365-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳cef-o365-app-activity-6 ↳cef-o365-app-activity-9 ↳o365-activity-3 ↳o365-activity-1 ↳cef-o365-app-activity-20 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 app-activity-failed ↳o365-activity ↳cef-microsoft-graph-activity-3 ↳cef-microsoft-graph-activity app-login ↳cef-o365-app-login ↳cef-o365-app-login-1 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳o365-sharepoint-app-activity ↳logrhythm-0365-failed-app-login ↳json-o365-failed-app-login dlp-email-alert-in ↳o365-email-alert ↳s-O365-dlp-email ↳json-o365-dlp-email ↳q-o365-dlp-email dlp-email-alert-in-failed ↳o365-inbox-activity ↳json-microsoft-app-activity-31 ↳microsoft-app-activity-12 ↳cef-microsoft-app-activity-29 ↳cef-microsoft-app-activity-28 ↳microsoft-app-activity-11 ↳microsoft-app-activity-10 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳cef-microsoft-app-activity-24 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳microsoft-app-activity-4 ↳microsoft-app-activity-6 ↳cef-microsoft-app-activity-39 ↳microsoft-app-activity-5 ↳microsoft-app-activity-8 ↳microsoft-app-activity-7 ↳microsoft-app-activity-9 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 dlp-email-alert-out ↳json-email-saas-o365-alert ↳cef-O365-dlp-email-out ↳o365-email-alert ↳s-O365-dlp-email ↳json-o365-dlp-email ↳q-o365-dlp-email ↳s-O365-email ↳o365-dlp-email-out-1 ↳o365-dlp-email-out-2 ↳xml-email-saas-o365-alert ↳o365-phishing-alert ↳cef-o365-dlp-email dlp-email-alert-out-failed ↳O365-email-alert-in ↳cef-O365-dlp-email-in ↳o365-email-alert ↳s-O365-dlp-email ↳json-o365-dlp-email ↳q-o365-dlp-email ↳cef-o365-file-read-7 ↳cef-o365-file-read-8 ↳logrhythm-o365-file-read-4 ↳logrhythm-o365-file-read-3 ↳logrhythm-o365-file-read-2 ↳cef-o365-file-read-3 ↳cef-o365-file-read-4 ↳cef-o365-file-read-5 ↳logrhythm-o365-file-activity ↳cef-o365-file-read-6 ↳logrhythm-o365-file-read-7 ↳cef-o365-file-read-1 ↳logrhythm-o365-file-read-6 ↳cef-o365-file-read-2 ↳logrhythm-o365-file-read ↳logrhythm-o365-file-read-5 failed-app-login ↳o365-activity ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳cef-o365-app-activity-6 ↳cef-o365-app-activity-9 ↳cef-o365-app-activity-20 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-microsoft-graph-activity-1 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-graph-activity-4 ↳cef-microsoft-graph-activity-6 ↳o365-teams-app-login ↳cef-o365-app-login ↳cef-o365-app-login-1 ↳o365-phishing-alert ↳cef-o365-dlp-email failed-logon ↳o365-dlp-policy-alert ↳o365-dlp-alert file-delete ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳cef-syslog-sharepoint-activity ↳o365-sharepoint-app-activity ↳azure-process-created file-download ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳microsoft-app-activity-2 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳microsoft-app-activity-1 ↳o365-sharepoint-app-activity file-permission-change ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳cef-syslog-sharepoint-activity ↳o365-sharepoint-app-activity file-read ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳cef-syslog-sharepoint-activity ↳o365-sharepoint-app-activity ↳logrhythm-o365-file-write-4 ↳logrhythm-o365-file-write-5 ↳json-o365-file-write-7 ↳logrhythm-o365-file-write-6 ↳logrhythm-o365-file-write ↳logrhythm-o365-file-write-7 ↳logrhythm-o365-file-write-2 ↳logrhythm-o365-file-write-3 ↳cef-o365-file-write-9 ↳cef-o365-file-write-8 ↳cef-o365-file-write-7 ↳cef-o365-file-write-6 ↳cef-o365-file-write-1 ↳cef-o365-file-write-5 ↳logrhythm-o365-file-write-8 ↳cef-o365-file-write-4 ↳cef-o365-file-write-11 ↳cef-o365-file-write-3 ↳cef-o365-file-write-10 ↳cef-o365-file-write-2 ↳json-microsoft-app-activity-17 file-upload ↳o365-activity ↳cef-o365-app-activity-3 ↳json-o365-activity-3 ↳o365-mip-label-activity ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳cef-o365-app-activity-6 ↳cef-o365-app-activity-9 ↳o365-activity-3 ↳o365-activity-1 ↳cef-o365-app-activity-20 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳o365-powerbi-activity ↳o365-teams-activity-1 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳cef-syslog-sharepoint-activity ↳o365-sharepoint-app-activity file-write ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳o365-sharepoint-app-activity ↳logrhythm-o365-file-upload ↳cef-o365-file-delete-1 ↳logrhythm-o365-file-delete-3 ↳logrhythm-o365-file-delete-2 ↳json-microsoft-app-activity-19 ↳logrhythm-o365-file-delete ↳cef-o365-file-delete-2 ntlm-logon ↳json-email-saas-o365-alert ↳cef-O365-dlp-email-out ↳o365-email-alert ↳s-O365-dlp-email ↳json-o365-dlp-email ↳q-o365-dlp-email ↳s-O365-email ↳o365-dlp-email-out-1 ↳o365-dlp-email-out-2 ↳xml-email-saas-o365-alert ↳cef-O365-dlp-email-out-1 ↳O365-email-alert-out process-created ↳cef-o365-dlp-alert ↳logrhythm-0365-account-password-change remote-logon ↳o365-inbox-rules-move-to-folder ↳o365-inbox-rules-all-2 ↳o365-inbox-rules ↳o365-inbox-rules-all ↳o365-inbox-rules-forward-to-1 ↳o365-inbox-rules-forward-to ↳o365-inbox-rules-2 ↳cef-microsoft-app-activity-inbox-rule security-alert ↳o365-security-alert ↳o365-url-click-alert ↳o365-malware-alert ↳o365-security-alert-1 ↳o365-signin-alert ↳o365-security-alert-3 ↳o365-security-alert-2 ↳o365-mal-url-click ↳cef-o365-security-alert T1021 - Remote ServicesT1078 - Valid AccountsT1078.003 - Valid Accounts: Local AccountsT1110 - Brute ForceT1133 - External Remote Services 65 Rules28 Models Account Manipulation account-disabled ↳logrhythm-0365-app-login ↳json-o365-app-login app-activity ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳o365-activity ↳cef-o365-app-activity-3 ↳json-o365-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳cef-o365-app-activity-6 ↳cef-o365-app-activity-9 ↳o365-activity-3 ↳o365-activity-1 ↳cef-o365-app-activity-20 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 app-activity-failed ↳o365-activity ↳cef-microsoft-graph-activity-3 ↳cef-microsoft-graph-activity app-login ↳cef-o365-app-login ↳cef-o365-app-login-1 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳o365-sharepoint-app-activity ↳logrhythm-0365-failed-app-login ↳json-o365-failed-app-login dlp-email-alert-in ↳o365-email-alert ↳s-O365-dlp-email ↳json-o365-dlp-email ↳q-o365-dlp-email dlp-email-alert-in-failed ↳o365-inbox-activity ↳json-microsoft-app-activity-31 ↳microsoft-app-activity-12 ↳cef-microsoft-app-activity-29 ↳cef-microsoft-app-activity-28 ↳microsoft-app-activity-11 ↳microsoft-app-activity-10 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳cef-microsoft-app-activity-24 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳microsoft-app-activity-4 ↳microsoft-app-activity-6 ↳cef-microsoft-app-activity-39 ↳microsoft-app-activity-5 ↳microsoft-app-activity-8 ↳microsoft-app-activity-7 ↳microsoft-app-activity-9 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 dlp-email-alert-out ↳json-email-saas-o365-alert ↳cef-O365-dlp-email-out ↳o365-email-alert ↳s-O365-dlp-email ↳json-o365-dlp-email ↳q-o365-dlp-email ↳s-O365-email ↳o365-dlp-email-out-1 ↳o365-dlp-email-out-2 ↳xml-email-saas-o365-alert ↳o365-phishing-alert ↳cef-o365-dlp-email dlp-email-alert-out-failed ↳O365-email-alert-in ↳cef-O365-dlp-email-in ↳o365-email-alert ↳s-O365-dlp-email ↳json-o365-dlp-email ↳q-o365-dlp-email ↳cef-o365-file-read-7 ↳cef-o365-file-read-8 ↳logrhythm-o365-file-read-4 ↳logrhythm-o365-file-read-3 ↳logrhythm-o365-file-read-2 ↳cef-o365-file-read-3 ↳cef-o365-file-read-4 ↳cef-o365-file-read-5 ↳logrhythm-o365-file-activity ↳cef-o365-file-read-6 ↳logrhythm-o365-file-read-7 ↳cef-o365-file-read-1 ↳logrhythm-o365-file-read-6 ↳cef-o365-file-read-2 ↳logrhythm-o365-file-read ↳logrhythm-o365-file-read-5 failed-app-login ↳o365-activity ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳cef-o365-app-activity-6 ↳cef-o365-app-activity-9 ↳cef-o365-app-activity-20 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-microsoft-graph-activity-1 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-graph-activity-4 ↳cef-microsoft-graph-activity-6 ↳o365-teams-app-login ↳cef-o365-app-login ↳cef-o365-app-login-1 ↳o365-phishing-alert ↳cef-o365-dlp-email failed-logon ↳o365-dlp-policy-alert ↳o365-dlp-alert file-delete ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳cef-syslog-sharepoint-activity ↳o365-sharepoint-app-activity ↳azure-process-created file-download ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳microsoft-app-activity-2 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳microsoft-app-activity-1 ↳o365-sharepoint-app-activity file-permission-change ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳cef-syslog-sharepoint-activity ↳o365-sharepoint-app-activity file-read ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳cef-syslog-sharepoint-activity ↳o365-sharepoint-app-activity ↳logrhythm-o365-file-write-4 ↳logrhythm-o365-file-write-5 ↳json-o365-file-write-7 ↳logrhythm-o365-file-write-6 ↳logrhythm-o365-file-write ↳logrhythm-o365-file-write-7 ↳logrhythm-o365-file-write-2 ↳logrhythm-o365-file-write-3 ↳cef-o365-file-write-9 ↳cef-o365-file-write-8 ↳cef-o365-file-write-7 ↳cef-o365-file-write-6 ↳cef-o365-file-write-1 ↳cef-o365-file-write-5 ↳logrhythm-o365-file-write-8 ↳cef-o365-file-write-4 ↳cef-o365-file-write-11 ↳cef-o365-file-write-3 ↳cef-o365-file-write-10 ↳cef-o365-file-write-2 ↳json-microsoft-app-activity-17 file-upload ↳o365-activity ↳cef-o365-app-activity-3 ↳json-o365-activity-3 ↳o365-mip-label-activity ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳cef-o365-app-activity-6 ↳cef-o365-app-activity-9 ↳o365-activity-3 ↳o365-activity-1 ↳cef-o365-app-activity-20 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳o365-powerbi-activity ↳o365-teams-activity-1 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳cef-syslog-sharepoint-activity ↳o365-sharepoint-app-activity file-write ↳cef-o365-app-activity-3 ↳cef-o365-app-activity-4 ↳cef-o365-app-activity-1 ↳cef-o365-app-activity-2 ↳cef-o365-app-activity-7 ↳cef-o365-app-activity-21 ↳cef-o365-app-activity-8 ↳cef-o365-app-activity-22 ↳cef-o365-app-activity-5 ↳cef-o365-app-activity-23 ↳json-microsoft-app-activity-31 ↳cef-o365-app-activity-6 ↳cef-microsoft-app-activity-29 ↳cef-o365-app-activity-9 ↳cef-microsoft-app-activity-28 ↳cef-microsoft-app-activity-23 ↳cef-microsoft-app-activity-22 ↳cef-microsoft-app-activity-21 ↳cef-microsoft-app-activity-20 ↳cef-microsoft-app-activity-27 ↳o365-activity-3 ↳cef-microsoft-app-activity-26 ↳cef-microsoft-app-activity-25 ↳o365-activity-1 ↳cef-microsoft-app-activity-24 ↳cef-o365-app-activity-20 ↳cef-microsoft-app-activity-9 ↳cef-microsoft-app-activity-8 ↳json-microsoft-app-activity-6 ↳cef-microsoft-app-activity-7 ↳json-microsoft-app-activity-9 ↳cef-microsoft-app-activity-6 ↳json-microsoft-app-activity-8 ↳cef-microsoft-app-activity-5 ↳cef-microsoft-app-activity-4 ↳cef-microsoft-app-activity-3 ↳cef-microsoft-app-activity-2 ↳cef-microsoft-app-activity-1 ↳cef-microsoft-app-activity-19 ↳cef-microsoft-app-activity-18 ↳json-microsoft-app-activity-1 ↳cef-microsoft-app-activity-17 ↳json-microsoft-app-activity-2 ↳json-microsoft-app-activity-5 ↳cef-microsoft-app-activity-12 ↳cef-microsoft-app-activity-11 ↳cef-microsoft-app-activity-10 ↳cef-microsoft-app-activity-52 ↳cef-microsoft-app-activity-51 ↳o365-activity ↳json-o365-activity-3 ↳json-microsoft-app-activity-12 ↳json-microsoft-app-activity-11 ↳json-microsoft-app-activity-10 ↳cef-microsoft-app-activity-42 ↳cef-microsoft-app-activity-41 ↳cef-microsoft-app-activity-40 ↳cef-o365-app-activity-14 ↳cef-o365-app-activity-15 ↳cef-o365-app-activity-16 ↳cef-o365-app-activity-17 ↳cef-o365-app-activity-10 ↳cef-o365-app-activity-11 ↳cef-o365-app-activity-12 ↳cef-o365-app-activity-13 ↳cef-o365-app-activity-18 ↳cef-o365-app-activity-19 ↳cef-microsoft-app-activity-34 ↳cef-microsoft-app-activity-33 ↳cef-microsoft-app-activity-32 ↳cef-microsoft-app-activity-31 ↳cef-microsoft-app-activity-37 ↳cef-microsoft-app-activity-36 ↳cef-microsoft-app-activity-35 ↳cef-microsoft-app-activity-30 ↳o365-sharepoint-activity ↳o365-onedrive-app-activity ↳o365-sharepoint-app-activity ↳logrhythm-o365-file-upload ↳cef-o365-file-delete-1 ↳logrhythm-o365-file-delete-3 ↳logrhythm-o365-file-delete-2 ↳json-microsoft-app-activity-19 ↳logrhythm-o365-file-delete ↳cef-o365-file-delete-2 ntlm-logon ↳json-email-saas-o365-alert ↳cef-O365-dlp-email-out ↳o365-email-alert ↳s-O365-dlp-email ↳json-o365-dlp-email ↳q-o365-dlp-email ↳s-O365-email ↳o365-dlp-email-out-1 ↳o365-dlp-email-out-2 ↳xml-email-saas-o365-alert ↳cef-O365-dlp-email-out-1 ↳O365-email-alert-out process-created ↳cef-o365-dlp-alert ↳logrhythm-0365-account-password-change remote-logon ↳o365-inbox-rules-move-to-folder ↳o365-inbox-rules-all-2 ↳o365-inbox-rules ↳o365-inbox-rules-all ↳o365-inbox-rules-forward-to-1 ↳o365-inbox-rules-forward-to ↳o365-inbox-rules-2 ↳cef-microsoft-app-activity-inbox-rule security-alert ↳o365-security-alert ↳o365-url-click-alert ↳o365-malware-alert ↳o365-security-alert-1 ↳o365-signin-alert ↳o365-security-alert-3 ↳o365-security-alert-2 ↳o365-mal-url-click ↳cef-o365-security-alert T1003 - OS Credential DumpingT1047 - Windows Management InstrumentationT1078 - Valid AccountsT1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate PermissionsT1136 - Create AccountT1136.001 - Create Account: Create: Local AccountT1175 - T1175T1531 - Account Access Removal 22 Rules9 Models Next Page -->> ATT&CK Matrix for Enterprise Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact External Remote ServicesValid AccountsExploit Public Fasing ApplicationPhishing Windows Management InstrumentationCommand and Scripting InterperterScheduled Task/JobScriptingSystem ServicesExploitation for Client ExecutionUser ExecutionScheduled Task/Job: Scheduled TaskCommand and Scripting Interperter: PowerShellScheduled Task/Job: At (Windows) Pre-OS BootCreate AccountCreate or Modify System ProcessExternal Remote ServicesValid AccountsHijack Execution FlowServer Software Component: Web ShellAccount ManipulationBITS JobsCreate or Modify System Process: Windows ServiceScheduled Task/JobServer Software ComponentEvent Triggered ExecutionBoot or Logon Autostart ExecutionCreate Account: Create: Local AccountAccount Manipulation: Exchange Email Delegate Permissions Access Token Manipulation: Token Impersonation/TheftCreate or Modify System ProcessValid AccountsAccess Token ManipulationExploitation for Privilege EscalationHijack Execution FlowProcess InjectionScheduled Task/JobAbuse Elevation Control MechanismEvent Triggered ExecutionBoot or Logon Autostart ExecutionProcess Injection: Dynamic-link Library InjectionAbuse Elevation Control Mechanism: Bypass User Account Control Hide ArtifactsIndirect Command ExecutionImpair DefensesIndicator Removal on Host: Clear Windows Event LogsTrusted Developer Utilities Proxy ExecutionMasquerading: Match Legitimate Name or LocationMasquerading: Rename System UtilitiesFile and Directory Permissions Modification: Windows File and Directory Permissions ModificationObfuscated Files or Information: Compile After DeliveryObfuscated Files or Information: Indicator Removal from ToolsHijack Execution Flow: DLL Side-LoadingIndicator Removal on Host: File DeletionMasqueradingValid AccountsModify RegistryBITS JobsUse Alternate Authentication MaterialHide Artifacts: NTFS File AttributesUse Alternate Authentication Material: Pass the HashIndicator Removal on HostUse Alternate Authentication Material: Web Session CookieUse Alternate Authentication Material: Pass the TicketPre-OS BootFile and Directory Permissions ModificationXSL Script ProcessingDeobfuscate/Decode Files or InformationAbuse Elevation Control MechanismImpair Defenses: Disable or Modify System FirewallObfuscated Files or InformationSigned Binary Proxy Execution: Compiled HTML FileAccess Token ManipulationExploitation for Defense EvasionHijack Execution FlowProcess InjectionValid Accounts: Local AccountsSigned Binary Proxy Execution: MsiexecSigned Binary Proxy ExecutionSigned Binary Proxy Execution: Regsvcs/RegasmSigned Binary Proxy Execution: CMSTPSigned Binary Proxy Execution: Control PanelSigned Binary Proxy Execution: InstallUtilSigned Binary Proxy Execution: Regsvr32Trusted Developer Utilities Proxy Execution: MSBuildSigned Binary Proxy Execution: Rundll32 OS Credential DumpingInput CaptureUnsecured CredentialsBrute ForceMan-in-the-MiddleSteal or Forge Kerberos TicketsSteal or Forge Kerberos Tickets: KerberoastingNetwork Sniffing Network Service ScanningAccount DiscoveryDomain Trust DiscoveryAccount Discovery: Local AccountAccount Discovery: Domain AccountFile and Directory DiscoveryNetwork SniffingSystem Information DiscoveryNetwork Share DiscoveryQuery RegistryProcess DiscoverySystem Owner/User DiscoverySystem Network Configuration Discovery Exploitation of Remote ServicesRemote ServicesRemote Services: SMB/Windows Admin SharesUse Alternate Authentication MaterialRemote Services: Remote Desktop Protocol Email CollectionInput CaptureAudio CaptureArchive Collected DataMan-in-the-MiddleEmail Collection: Email Forwarding Rule Data EncodingData Encoding: Standard EncodingRemote Access SoftwareIngress Tool TransferProxy: Multi-hop ProxyApplication Layer ProtocolProxy Exfiltration Over Alternative ProtocolExfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolAutomated Exfiltration Account Access RemovalResource HijackingData Encrypted for ImpactInhibit System Recovery