Azure-Sentinel/Hunting Queries/OfficeActivity
Shain Wray (MSTIC) 54b4792b1c Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
..
AnomolousUserAccessingOtherUsersMailbox.yaml DNS to Syslog changes 2021-08-04 15:49:57 -07:00
ExternalUserAddedRemovedInTeams_HuntVersion.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
ExternalUserFromNewOrgAddedToTeams.yaml DNS to Syslog changes 2021-08-04 15:49:57 -07:00
Mail_redirect_via_ExO_transport_rule_hunting.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
MultiTeamBot.yaml Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
MultiTeamOwner.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
MultipleTeamsDeletes.yaml Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
NewBotAddedToTeams.yaml Fixes 2021-08-06 14:12:37 -07:00
New_WindowsReservedFileNamesOnOfficeFileServices.yaml DNS to Syslog changes 2021-08-04 15:49:57 -07:00
OfficeMailForwarding_hunting.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
TeamsFilesUploaded.yaml Moving Teams queries out of folder and removing duplicates, plus mapping entities 2021-02-19 10:08:52 -08:00
UserAddToTeamsAndUploadsFile.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
WindowsReservedFileNamesOnOfficeFileServices.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
double_file_ext_exes.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
new_adminaccountactivity.yaml Fixes 2021-08-06 14:12:37 -07:00
new_sharepoint_downloads_by_IP.yaml Fixes 2021-08-06 14:12:37 -07:00
new_sharepoint_downloads_by_UserAgent.yaml Fixes 2021-08-06 14:12:37 -07:00
nonowner_MailboxLogin.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
powershell_or_nonbrowser_MailboxLogin.yaml Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
sharepoint_downloads.yaml Fixes 2021-08-06 14:12:37 -07:00