Update MultipleTeamsDeletes.yaml
Updated as per review comments.
This commit is contained in:
Родитель
4e13190b94
Коммит
70f4306c0a
|
@ -3,6 +3,15 @@ name: Multiple Teams deleted by a single user
|
|||
description: |
|
||||
'This detection flags the occurrences of deleting multiple teams within an hour.
|
||||
This data is a part of Office 365 Connector in Azure Sentinel.'
|
||||
severity: Low
|
||||
requiredDataConnectors:
|
||||
- connectorId: Office365
|
||||
dataTypes:
|
||||
- OfficeActivity (Teams)
|
||||
queryFrequency: 1d
|
||||
queryPeriod: 1d
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Impact
|
||||
relevantTechniques:
|
||||
|
|
Загрузка…
Ссылка в новой задаче