Skip to content

Commit

Permalink
Update MailItemsAccessedTimeSeries.yaml
Browse files Browse the repository at this point in the history
  • Loading branch information
shainw authored Feb 3, 2025
1 parent 03d2380 commit 750d63d
Showing 1 changed file with 3 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ description: |
The query leverages KQL built-in anomaly detection algorithms to find large deviations from baseline patterns.
Sudden increases in execution frequency of sensitive actions should be further investigated for malicious activity.
Manually change scorethreshold from 1.5 to 3 or higher to reduce the noise based on outliers flagged from the query criteria.
Read more about MailItemsAccessed- https://docs.microsoft.com/microsoft-365/compliance/advanced-audit?view=o365-worldwide#mailitemsaccessed'
Read more about MailItemsAccessed- https://learn.microsoft.com/en-us/purview/audit-log-investigate-accounts'
severity: Medium
status: Available
requiredDataConnectors:
Expand Down Expand Up @@ -76,5 +76,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: SourceIPMax
version: 2.0.5
kind: Scheduled
version: 2.0.6
kind: Scheduled

0 comments on commit 750d63d

Please sign in to comment.