-
Notifications
You must be signed in to change notification settings - Fork 605
[Rule Tuning] M365 Impossible / Atypical Travel FN #5267
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Rule: Tuning - GuidelinesThese guidelines serve as a reminder set of considerations when tuning an existing rule. Documentation and Context
Rule Metadata Checks
Testing and Validation
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm.
FWIW I saw your original note when these fields were introduced, but it's unclear why those specifically were the only ones selected.
IMPORTANT: o365.audit.Target.ID must have a resource ID for OfficeHome or Microsoft Office Portal
These were M365 portal first party IDs, however, the Exchange ID listed by the community member is Exchange authentication in general which is valid for monitoring for atypical / impossible travel, just not part of the original scope to only focus on Portal logins. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updates look good and make sense 👍
Validated in Trade Stack 🟢
Fixes #5239
Pull Request
Issue link(s):
Summary - What I changed
Tunes M365 authentication rules to address FNs identified by a community member. Confirmed the inclusion does indeed introduce potential FNs at the expense of higher volume. There are too many first-party clients where atypical / impossible travel could occur and be accounted for. Will monitor new version alerts and tune by noisy client IDs and/or user agents (mobile). Please see related issue for more details.
How To Test
Checklist
bug,enhancement,schema,maintenance,Rule: New,Rule: Deprecation,Rule: Tuning,Hunt: New, orHunt: Tuningso guidelines can be generatedmeta:rapid-mergelabel if planning to merge within 24 hoursContributor checklist