Office 365 Admin Commands Run By User

  • Office 365 - Admin Commands Run by User

Configuration

query

name:Run command NOT requestClientApplication:Client=MSExchangeRPC NOT requestClientApplication:Microsoft.Exchange.Data.StoreObjects.ClientInfo NOT uniqueServiceAppIds:APPID_OUTLOOK NOT suser:aisadmin* NOT targetObjects:Get-Dlp* NOT task: SupervisoryReviewOLAudit NOT task: Delete-QuarantineMessage

config

Key | Value — | — type | aggregation-v1 query | name:Run command NOT requestClientApplication:Client=MSExchangeRPC NOT requestClientApplication:Microsoft.Exchange.Data.StoreObjects.ClientInfo NOT uniqueServiceAppIds:APPID_OUTLOOK NOT suser:aisadmin* NOT targetObjects:Get-Dlp* NOT task: SupervisoryReviewOLAudit NOT task: Delete-QuarantineMessage streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000

SIEM Office 365 Alerts

SIEM Office 365 Alerts.


Last modified December 31, 1969