Skip to content

Commit

Permalink
Merge pull request SigmaHQ#2237 from frack113/m365
Browse files Browse the repository at this point in the history
standardization m365
  • Loading branch information
frack113 authored Nov 10, 2021
2 parents c14322d + 3430943 commit ca17949
Show file tree
Hide file tree
Showing 13 changed files with 43 additions and 42 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: m365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: m365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: m365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: m365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatDetection
service: m365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: Office365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: m365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: Microsoft365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: m365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: m365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: Microsoft365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ references:
- https://docs.microsoft.com/en-us/cloud-app-security/policy-template-reference
logsource:
category: ThreatManagement
service: Microsoft365
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
Expand Down
61 changes: 31 additions & 30 deletions tools/config/generic/m365.yml
Original file line number Diff line number Diff line change
@@ -1,32 +1,33 @@
title: Microsoft 365 Rules
order: 10
ThreatManagement:
product: m365
category: ThreatManagement
conditions:
eventSource: SecurityComplianceCenter
AccessGovernance:
product: m365
category: AccessGovernance
conditions:
eventSource: SecurityComplianceCenter
CloudDiscovery:
product: m365
category: CloudDiscovery
conditions:
eventSource: SecurityComplianceCenter
DataLossPrevention:
product: m365
category: DataLossPrevention
conditions:
eventSource: SecurityComplianceCenter
ThreatDetection:
product: m365
category: ThreatDetection
conditions:
eventSource: SecurityComplianceCenter
SharingControl:
product: m365
category: SharingControl
conditions:
eventSource: SecurityComplianceCenter
logsources:
ThreatManagement:
product: m365
category: ThreatManagement
conditions:
eventSource: SecurityComplianceCenter
AccessGovernance:
product: m365
category: AccessGovernance
conditions:
eventSource: SecurityComplianceCenter
CloudDiscovery:
product: m365
category: CloudDiscovery
conditions:
eventSource: SecurityComplianceCenter
DataLossPrevention:
product: m365
category: DataLossPrevention
conditions:
eventSource: SecurityComplianceCenter
ThreatDetection:
product: m365
category: ThreatDetection
conditions:
eventSource: SecurityComplianceCenter
SharingControl:
product: m365
category: SharingControl
conditions:
eventSource: SecurityComplianceCenter

0 comments on commit ca17949

Please sign in to comment.