Update MultipleTeamsDeletes.yaml
Updated as per review comments.
This commit is contained in:
Родитель
4e13190b94
Коммит
70f4306c0a
|
@ -3,6 +3,15 @@ name: Multiple Teams deleted by a single user
|
||||||
description: |
|
description: |
|
||||||
'This detection flags the occurrences of deleting multiple teams within an hour.
|
'This detection flags the occurrences of deleting multiple teams within an hour.
|
||||||
This data is a part of Office 365 Connector in Azure Sentinel.'
|
This data is a part of Office 365 Connector in Azure Sentinel.'
|
||||||
|
severity: Low
|
||||||
|
requiredDataConnectors:
|
||||||
|
- connectorId: Office365
|
||||||
|
dataTypes:
|
||||||
|
- OfficeActivity (Teams)
|
||||||
|
queryFrequency: 1d
|
||||||
|
queryPeriod: 1d
|
||||||
|
triggerOperator: gt
|
||||||
|
triggerThreshold: 0
|
||||||
tactics:
|
tactics:
|
||||||
- Impact
|
- Impact
|
||||||
relevantTechniques:
|
relevantTechniques:
|
||||||
|
|
Загрузка…
Ссылка в новой задаче