M365 coverage
222 M365 detection rules across 5 vendors covering 118 (Workload, Operation) pairs. Each RecordType and Operation maps to a catalog entry under the Microsoft 365, Entra ID & Azure catalog.AzureActiveDirectory
Add a partner to cross-tenant access setting. 1 rule
Add app role assignment grant to user. 1 rule
Add app role assignment to service principal. 1 rule
Add application. 3 rules
Add eligible member to role. 2 rules
Add group. 2 rules
Add member to group. 2 rules
Add member to role. 6 rules
Add owner to application. 1 rule
Add registered users to device. 1 rule
Add service principal. 2 rules
Add user* 1 rule
Consent to application. 5 rules
Delete group. 1 rule
Delete partner specific cross-tenant access setting. 1 rule
PasswordLogonInitialAuthUsingPassword 2 rules
Remove member from group. 1 rule
Update application. 8 rules
Update authorization policy. 1 rule
Update policy. 1 rule
Update user. 1 rule
UserLoggedIn 16 rules
UserLoginFailed 10 rules
Exchange
*AntiPhish* 1 rule
*Malware* 1 rule
*SafeAttachment* 1 rule
*SafeLink* 1 rule
*TransportRule 1 rule
Add-FederatedDomain 1 rule
Add-MailboxFolderPermission 2 rules
Add-MailboxPermission 3 rules
Add-RecipientPermission 1 rule
AddFolderPermissions 1 rule
Disable-* 2 rules
Disable-AntiPhishRule 1 rule
Disable-MalwareFilterRule 1 rule
Disable-SafeAttachmentRule 1 rule
Disable-SafeLinksRule 1 rule
Disable-TransportRule 1 rule
HardDelete 6 rules
MailItemsAccessed 7 rules
ModifyFolderPermissions 2 rules
MoveToDeletedItems 1 rule
New-AcceptedDomain 1 rule
New-InboxRule 8 rules
New-ManagementRoleAssignment 2 rules
New-TransportRule 4 rules
PasswordLogonInitialAuthUsingPassword 2 rules
Remove-* 2 rules
Remove-AcceptedDomain 1 rule
Remove-AntiPhishPolicy 1 rule
Remove-AntiPhishRule 1 rule
Remove-DlpPolicy 1 rule
Remove-FederatedDomain 1 rule
Remove-MalwareFilterPolicy 1 rule
Remove-MalwareFilterRule 1 rule
Remove-TransportRule 1 rule
Send 1 rule
Send* 2 rules
SendAs 1 rule
SendOnBehalf 1 rule
Set-AcceptedDomain 1 rule
Set-AdminAuditLogConfig 3 rules
Set-DkimSigningConfig 1 rule
Set-InboxRule 6 rules
Set-Mailbox 3 rules
Set-MailboxAuditBypassAssociation 1 rule
Set-MailboxFolderPermission 1 rule
Set-MsolDomainFederationSettings 1 rule
Set-TransportRule 4 rules
SoftDelete 2 rules
UserLoginFailed 2 rules
MicrosoftTeams
FileAccessed 1 rule
FileUploaded 1 rule
MemberAdded 1 rule
MemberRemoved 2 rules
Set-CsTeamsClientConfiguration 1 rule
Set-CsTenantFederationConfiguration 1 rule
TeamDeleted 1 rule
TeamsTenantSettingChanged 1 rule
OneDrive
FileAccessed 1 rule
FileDownloaded 4 rules
FileMalwareDetected 1 rule
FileSyncDownloadedFull 2 rules
FileSyncUploadedFull 2 rules
FileUploaded 2 rules
SharingPolicyChanged 1 rule
SiteCollectionAdminAdded 1 rule
SecurityComplianceCenter
AdminMailAccess 1 rule
AdminSubmission 1 rule
AlertEntityGenerated 3 rules
AlertTriggered 1 rule
Unusual volume of file deletion 1 rule
User restricted from sending email 1 rule
SkypeForBusiness
Set-CsTeamsClientConfiguration 1 rule
Set-CsTenantFederationConfiguration 1 rule
ThreatIntelligence
AtpDetection 1 rule
(unattributed)
(any) 61 rules