-
Notifications
You must be signed in to change notification settings - Fork 587
Open
Labels
Domain: Cloud WorkloadsIntegration: Azureazure related rulesazure related rulesRule: NewProposal for new ruleProposal for new rulebacklogv7.14.07.14 rules release package7.14 rules release package
Description
Description
Hardening Strategies for Microsoft 365 to Defend Against UNC2452 - thanks to @dstepanic17 for sharing the whitepaper.
The Azure AD Audit log and Unified Audit log records when a domain is configured for federated authentication and the modification of federated realm objects. In most organizations, domain federation settings will be updated infrequently. Organizations should create rules to alert on the log events generated by these activities and audit them to ensure they are legitimate.
Required Info
- Eventing Sources:
- Target Operating Systems:
- Platforms
- Target ECS Version: x.x.x
- New fields required in ECS for this?
- Related issues or PRs
Optional Info
Example Data
“Operation”: “Set domain authentication.”
“Operation”: “Set federation settings on domain.”
Metadata
Metadata
Assignees
Labels
Domain: Cloud WorkloadsIntegration: Azureazure related rulesazure related rulesRule: NewProposal for new ruleProposal for new rulebacklogv7.14.07.14 rules release package7.14 rules release package