Intune-Application
any: Application (catch-all)
#Description
Synthetic aggregation for Intune audit rules that filter the Application category without a specific activityType. Not a distinct audit record.
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Create IntuneBrandingProfile
#Description
Create a group targeted branding profile.
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Example Audit Record #
{
"id": "b6620a32-3129-430a-b468-e39aad1e4743",
"displayName": "Create a group targeted branding profile.",
"componentName": "MobileApp",
"activity": null,
"activityDateTime": "2026-07-04T18:40:39.1454313Z",
"activityType": "Create IntuneBrandingProfile",
"activityOperationType": "Create",
"activityResult": "Success",
"correlationId": "50d15e86-5d98-454a-9890-ab9d93ce0ff5",
"category": "Application",
"actor": {
"auditActorType": "ItPro",
"userPermissions": [
"*"
],
"applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
"applicationDisplayName": "Microsoft Graph Command Line Tools",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"servicePrincipalName": null,
"ipAddress": null,
"userId": "33333333-3333-3333-3333-333333333333"
},
"resources": [
{
"displayName": "dwharn-2d37281a",
"auditResourceType": "IntuneBrandingProfile",
"resourceId": "06d17e54-0dac-41a3-bbad-e5307220e21f",
"modifiedProperties": [
{
"displayName": "ProfileName",
"oldValue": null,
"newValue": "dwharn-2d37281a"
},
{
"displayName": "ThemeColor",
"oldValue": null,
"newValue": "R=0, G=114, B=198"
},
{
"displayName": "ShowLogo",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "ShowDisplayNameNextToLogo",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "SendDeviceOwnershipChangePushNotification",
"oldValue": null,
"newValue": "True"
},
{
"displayName": "EnrollmentAvailability",
"oldValue": null,
"newValue": "AvailableWithPrompts"
},
{
"displayName": "DisableDeviceCategorySelection",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "ShowAzureADEnterpriseApps",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "ShowOfficeWebApps",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "ShowConfigurationManagerApps",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "DisableClientTelemetry",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "RoleScopeTagIds",
"oldValue": null,
"newValue": "Default"
},
{
"displayName": "CompanyPortalBlockedActions",
"oldValue": null,
"newValue": "6,1,1"
},
{
"displayName": "DeviceManagementAPIVersion",
"oldValue": null,
"newValue": "5025-09-30"
}
]
}
]
}
Create ManagedDeviceMobileAppConfiguration
#Description
Create iOS app configuration policy
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Example Audit Record #
{
"id": "e63f5afa-8875-4423-8bc2-e78cc2f21e34",
"displayName": "Create iOS app configuration policy",
"componentName": "MobileAppConfiguration",
"activity": null,
"activityDateTime": "2026-07-04T18:40:33.0108931Z",
"activityType": "Create ManagedDeviceMobileAppConfiguration",
"activityOperationType": "Create",
"activityResult": "Success",
"correlationId": "7a01a6ee-92db-40bb-a5d7-57db80b94e16",
"category": "Application",
"actor": {
"auditActorType": "ItPro",
"userPermissions": [
"*"
],
"applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
"applicationDisplayName": "Microsoft Graph Command Line Tools",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"servicePrincipalName": null,
"ipAddress": null,
"userId": "33333333-3333-3333-3333-333333333333"
},
"resources": [
{
"displayName": "dwharn-2d37281a",
"auditResourceType": "IOSMobileAppConfiguration",
"resourceId": "5cb8b1d0-8e2d-4d65-8b5d-15f66d582582",
"modifiedProperties": [
{
"displayName": "TargetedMobileApps",
"oldValue": null,
"newValue": []
},
{
"displayName": "EncodedSettingXml",
"oldValue": null,
"newValue": "PGRpY3QgLz4="
},
{
"displayName": "SettingXml",
"oldValue": null,
"newValue": "<dict />"
},
{
"displayName": "Id",
"oldValue": null,
"newValue": "5cb8b1d0-8e2d-4d65-8b5d-15f66d582582"
},
{
"displayName": "CreatedDateTime",
"oldValue": null,
"newValue": "7/4/2026 6:40:32 PM"
},
{
"displayName": "Description",
"oldValue": null,
"newValue": "<null>"
},
{
"displayName": "LastModifiedDateTime",
"oldValue": null,
"newValue": "7/4/2026 6:40:32 PM"
},
{
"displayName": "Version",
"oldValue": null,
"newValue": "1"
},
{
"displayName": "DeviceManagementAPIVersion",
"oldValue": null,
"newValue": "5026-04-26"
},
{
"displayName": "$Collection.RoleScopeTagIds[0]",
"oldValue": null,
"newValue": "Default"
}
]
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1021, T1021.007, T1072, T1105, T1202↳ also matches Create MobileApp, Create MobileAppCategory, Delete ManagedDeviceMobileAppConfiguration, Delete MobileApp, Delete MobileAppCategory
Create MobileApp
#Description
Create application.
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Example Audit Record #
{
"id": "525a7b6a-751f-42e4-8d22-fab160caf8b8",
"displayName": "Create application.",
"componentName": "MobileApp",
"activity": null,
"activityDateTime": "2026-07-04T18:40:30.311818Z",
"activityType": "Create MobileApp",
"activityOperationType": "Create",
"activityResult": "Success",
"correlationId": "637f03b6-1d5e-425c-bc94-746f37b1e1c0",
"category": "Application",
"actor": {
"auditActorType": "ItPro",
"userPermissions": [
"*"
],
"applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
"applicationDisplayName": "Microsoft Graph Command Line Tools",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"servicePrincipalName": null,
"ipAddress": null,
"userId": "33333333-3333-3333-3333-333333333333"
},
"resources": [
{
"displayName": "dwharn-2d37281a",
"auditResourceType": "WebApp",
"resourceId": "a7b6cdb3-02a9-4853-990f-a4608a83a32d",
"modifiedProperties": [
{
"displayName": "AppUrl",
"oldValue": null,
"newValue": "https://example.com"
},
{
"displayName": "UseManagedBrowser",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "Id",
"oldValue": null,
"newValue": "a7b6cdb3-02a9-4853-990f-a4608a83a32d"
},
{
"displayName": "Description",
"oldValue": null,
"newValue": "<null>"
},
{
"displayName": "Publisher",
"oldValue": null,
"newValue": "detection.wiki"
},
{
"displayName": "CreatedDateTime",
"oldValue": null,
"newValue": "7/4/2026 6:40:29 PM"
},
{
"displayName": "LastModifiedDateTime",
"oldValue": null,
"newValue": "7/4/2026 6:40:29 PM"
},
{
"displayName": "IsFeatured",
"oldValue": null,
"newValue": "False"
},
{
"displayName": "PrivacyInformationUrl",
"oldValue": null,
"newValue": "<null>"
},
{
"displayName": "InformationUrl",
"oldValue": null,
"newValue": "<null>"
},
{
"displayName": "Owner",
"oldValue": null,
"newValue": "<null>"
},
{
"displayName": "Developer",
"oldValue": null,
"newValue": "<null>"
},
{
"displayName": "Notes",
"oldValue": null,
"newValue": "<null>"
},
{
"displayName": "PublishingState",
"oldValue": null,
"newValue": "Published"
},
{
"displayName": "DeviceManagementAPIVersion",
"oldValue": null,
"newValue": "2025-07-02"
}
]
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1021, T1021.007, T1072, T1105, T1202↳ also matches Create ManagedDeviceMobileAppConfiguration, Create MobileAppCategory, Delete ManagedDeviceMobileAppConfiguration, Delete MobileApp, Delete MobileAppCategory Panther #
T1021.007, T1072, T1202
Create MobileAppCategory
#Description
Create application category.
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Example Audit Record #
{
"id": "a9964589-db0d-4961-bafa-2c2574097ad0",
"displayName": "Create application category.",
"componentName": "MobileApp",
"activity": null,
"activityDateTime": "2026-07-04T18:40:31.6472294Z",
"activityType": "Create MobileAppCategory",
"activityOperationType": "Create",
"activityResult": "Success",
"correlationId": "2b3b7d22-aea0-4781-b9e9-800f9eacbe2b",
"category": "Application",
"actor": {
"auditActorType": "ItPro",
"userPermissions": [
"*"
],
"applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
"applicationDisplayName": "Microsoft Graph Command Line Tools",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"servicePrincipalName": null,
"ipAddress": null,
"userId": "33333333-3333-3333-3333-333333333333"
},
"resources": [
{
"displayName": "dwharn-2d37281a",
"auditResourceType": "MobileAppCategory",
"resourceId": "1e52293f-5e1e-4319-842b-7a88608c37bd",
"modifiedProperties": [
{
"displayName": "Id",
"oldValue": null,
"newValue": "1e52293f-5e1e-4319-842b-7a88608c37bd"
},
{
"displayName": "LastModifiedDateTime",
"oldValue": null,
"newValue": "1/1/0001 12:00:00 AM"
},
{
"displayName": "DeviceManagementAPIVersion",
"oldValue": null,
"newValue": "2025-07-02"
}
]
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1021, T1021.007, T1072, T1105, T1202↳ also matches Create ManagedDeviceMobileAppConfiguration, Create MobileApp, Delete ManagedDeviceMobileAppConfiguration, Delete MobileApp, Delete MobileAppCategory
Delete IntuneBrandingProfile
#Description
Delete a BrandingProfile.
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Example Audit Record #
{
"id": "e079417e-e8cb-4418-ac6c-0fa7ad3cfe64",
"displayName": "Delete a BrandingProfile.",
"componentName": "MobileApp",
"activity": null,
"activityDateTime": "2026-07-04T18:40:39.7806243Z",
"activityType": "Delete IntuneBrandingProfile",
"activityOperationType": "Delete",
"activityResult": "Success",
"correlationId": "db6fa3c1-e03a-4b13-b887-3e20ac7b5b59",
"category": "Application",
"actor": {
"auditActorType": "ItPro",
"userPermissions": [
"*"
],
"applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
"applicationDisplayName": "Microsoft Graph Command Line Tools",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"servicePrincipalName": null,
"ipAddress": null,
"userId": "33333333-3333-3333-3333-333333333333"
},
"resources": [
{
"displayName": null,
"auditResourceType": "Microsoft.Management.Services.BrandingProfileCommon.BrandingProfile",
"resourceId": "06d17e54-0dac-41a3-bbad-e5307220e21f",
"modifiedProperties": [
{
"displayName": "DeviceManagementAPIVersion",
"oldValue": null,
"newValue": "5025-09-30"
}
]
}
]
}
Delete ManagedDeviceMobileAppConfiguration
#Description
Delete iOS app configuration policy
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Example Audit Record #
{
"id": "4251011f-f438-4bfa-81e9-991d558082d9",
"displayName": "Delete iOS app configuration policy",
"componentName": "MobileAppConfiguration",
"activity": null,
"activityDateTime": "2026-07-04T18:40:33.8215619Z",
"activityType": "Delete ManagedDeviceMobileAppConfiguration",
"activityOperationType": "Delete",
"activityResult": "Success",
"correlationId": "c7a190ec-f76e-4759-881b-84a9391d973d",
"category": "Application",
"actor": {
"auditActorType": "ItPro",
"userPermissions": [
"*"
],
"applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
"applicationDisplayName": "Microsoft Graph Command Line Tools",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"servicePrincipalName": null,
"ipAddress": null,
"userId": "33333333-3333-3333-3333-333333333333"
},
"resources": [
{
"displayName": "dwharn-2d37281a",
"auditResourceType": "IOSMobileAppConfiguration",
"resourceId": "5cb8b1d0-8e2d-4d65-8b5d-15f66d582582",
"modifiedProperties": [
{
"displayName": "Id",
"oldValue": "5cb8b1d0-8e2d-4d65-8b5d-15f66d582582",
"newValue": "<null>"
},
{
"displayName": "CreatedDateTime",
"oldValue": "7/4/2026 6:40:32 PM",
"newValue": "<null>"
},
{
"displayName": "Description",
"oldValue": "<null>",
"newValue": "<null>"
},
{
"displayName": "LastModifiedDateTime",
"oldValue": "7/4/2026 6:40:32 PM",
"newValue": "<null>"
},
{
"displayName": "Version",
"oldValue": "1",
"newValue": "<null>"
},
{
"displayName": "DeviceManagementAPIVersion",
"oldValue": null,
"newValue": "5026-04-26"
},
{
"displayName": "$Collection.RoleScopeTagIds[0]",
"oldValue": null,
"newValue": "<null>"
},
{
"displayName": "$Collection.RoleScopeTagIds[1]",
"oldValue": "Default",
"newValue": null
}
]
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1021, T1021.007, T1072, T1105, T1202↳ also matches Create ManagedDeviceMobileAppConfiguration, Create MobileApp, Create MobileAppCategory, Delete MobileApp, Delete MobileAppCategory
Delete MobileApp
#Description
Delete application.
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Example Audit Record #
{
"id": "a7e8f80d-3cb9-4dba-bb62-5a1876e929b6",
"displayName": "Delete application.",
"componentName": "MobileApp",
"activity": null,
"activityDateTime": "2026-07-04T18:40:31.0792541Z",
"activityType": "Delete MobileApp",
"activityOperationType": "Delete",
"activityResult": "Success",
"correlationId": "111ebe68-c46d-4e1b-9d72-54d7bb8c5e92",
"category": "Application",
"actor": {
"auditActorType": "ItPro",
"userPermissions": [
"*"
],
"applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
"applicationDisplayName": "Microsoft Graph Command Line Tools",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"servicePrincipalName": null,
"ipAddress": null,
"userId": "33333333-3333-3333-3333-333333333333"
},
"resources": [
{
"displayName": "dwharn-2d37281a",
"auditResourceType": "WebApp",
"resourceId": "a7b6cdb3-02a9-4853-990f-a4608a83a32d",
"modifiedProperties": [
{
"displayName": "AppUrl",
"oldValue": "https://example.com",
"newValue": "<null>"
},
{
"displayName": "UseManagedBrowser",
"oldValue": "False",
"newValue": "<null>"
},
{
"displayName": "Id",
"oldValue": "a7b6cdb3-02a9-4853-990f-a4608a83a32d",
"newValue": "<null>"
},
{
"displayName": "Description",
"oldValue": "<null>",
"newValue": "<null>"
},
{
"displayName": "Publisher",
"oldValue": "detection.wiki",
"newValue": "<null>"
},
{
"displayName": "CreatedDateTime",
"oldValue": "7/4/2026 6:40:29 PM",
"newValue": "<null>"
},
{
"displayName": "LastModifiedDateTime",
"oldValue": "7/4/2026 6:40:29 PM",
"newValue": "<null>"
},
{
"displayName": "IsFeatured",
"oldValue": "False",
"newValue": "<null>"
},
{
"displayName": "PrivacyInformationUrl",
"oldValue": "<null>",
"newValue": "<null>"
},
{
"displayName": "InformationUrl",
"oldValue": "<null>",
"newValue": "<null>"
},
{
"displayName": "Owner",
"oldValue": "<null>",
"newValue": "<null>"
},
{
"displayName": "Developer",
"oldValue": "<null>",
"newValue": "<null>"
},
{
"displayName": "Notes",
"oldValue": "<null>",
"newValue": "<null>"
},
{
"displayName": "PublishingState",
"oldValue": "Published",
"newValue": "<null>"
},
{
"displayName": "DeviceManagementAPIVersion",
"oldValue": null,
"newValue": "2025-07-02"
}
]
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1021, T1021.007, T1072, T1105, T1202↳ also matches Create ManagedDeviceMobileAppConfiguration, Create MobileApp, Create MobileAppCategory, Delete ManagedDeviceMobileAppConfiguration, Delete MobileAppCategory
Delete MobileAppCategory
#Description
Delete application category.
Fields #
| Name | Description |
|---|---|
activity Edm.String | Friendly name of the activity. |
activityDateTime Edm.DateTimeOffset | The date time in UTC when the activity was performed. |
activityOperationType Edm.String | The HTTP operation type of the activity. |
activityResult Edm.String | The result of the activity. |
activityType Edm.String | The type of activity that was being performed. |
actor graph.auditActor | AAD user and application that are associated with the audit event. |
category Edm.String | Audit category. |
componentName Edm.String | Component name. |
correlationId Edm.Guid | The client request Id that is used to correlate activity within the system. |
displayName Edm.String | Event display name. |
resources Collection(graph.auditResource) | Resources being modified. |
Example Audit Record #
{
"id": "25bcd1a9-5b4d-46a1-b532-fc569b74b64e",
"displayName": "Delete application category.",
"componentName": "MobileApp",
"activity": null,
"activityDateTime": "2026-07-04T18:40:32.1982613Z",
"activityType": "Delete MobileAppCategory",
"activityOperationType": "Delete",
"activityResult": "Success",
"correlationId": "b43f8a01-3138-4572-b23d-172a1a892b26",
"category": "Application",
"actor": {
"auditActorType": "ItPro",
"userPermissions": [
"*"
],
"applicationId": "14d82eec-204b-4c2f-b7e8-296a70dab67e",
"applicationDisplayName": "Microsoft Graph Command Line Tools",
"userPrincipalName": "adminuser@example.onmicrosoft.com",
"servicePrincipalName": null,
"ipAddress": null,
"userId": "33333333-3333-3333-3333-333333333333"
},
"resources": [
{
"displayName": null,
"auditResourceType": "MobileAppCategory",
"resourceId": "1e52293f-5e1e-4319-842b-7a88608c37bd",
"modifiedProperties": [
{
"displayName": "DeviceManagementAPIVersion",
"oldValue": null,
"newValue": "2025-07-02"
}
]
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1021, T1021.007, T1072, T1105, T1202↳ also matches Create ManagedDeviceMobileAppConfiguration, Create MobileApp, Create MobileAppCategory, Delete ManagedDeviceMobileAppConfiguration, Delete MobileApp