Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 1.28 KB

FIRST-S00046.md

File metadata and controls

33 lines (26 loc) · 1.28 KB

Rules: First Seen Client Generating MailIItemsAccessed Event from User

Description

This alert looks at a First Seen client accessing an Office 365/Exchange mail box item. The MailItemsAccessed may not always be enabled within an Entra/Azure/Office 365 tenant and is dependent on Microsoft licensing requirements. See the following guide from CISA for additional information on this event type and investigation steps: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-193a

Additional Details

Detail Value
Type First Seen
Category Collection
Apply Risk to Entities user_username
Signal Name First Seen Client Generating MailIItemsAccessed Event from {{user_username}}
Summary Expression A First Seen client was observed as accessing an Office 365 mail item since the baseline period.
Retention Window 7776000000
Baseline Window 1209600000
Baseline Type PER_ENTITY
Score/Severity Static: 4
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0009, _mitreAttackTechnique:T1114

Vendors and Products

Fields Used

Origin Field
Normalized Schema action
Normalized Schema metadata_product
Normalized Schema user_username