Security & Compliance Center alert events

OperationDescriptionSampleRule
anyCatch-all for M365-SecurityComplianceAlerts rules matching the RecordType but no specific Operation.NY
AlertEntityGeneratedAn entity was added to a Microsoft 365 security/compliance alert generated by an alert policy in the Microsoft Defender / Purview portal.YY
AlertTriggeredA Security & Compliance Center alert policy was triggered by activity matching the policy conditions.YY
AlertUpdatedThe status or details of a Security and Compliance alert were updated (for example triage or resolution).YN

any: Security & Compliance Center alert events (catch-all)

#
RecordType
SecurityComplianceAlerts

Description

Catch-all for M365-SecurityComplianceAlerts rules matching the RecordType but no specific Operation.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Name (elastic rule field)eqsecuritycompliancecenter1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Purview Security Compliance Signal source low: Collects alerts generated by Microsoft Purview (formerly Office 365 Security & Compliance Center) through the SecurityComplianceCenter provider. These alerts represent policy violations, compliance issues, and threats detected by Microsoft Purview's built-in detection capabilities including DLP policy matches, eDiscovery actions, retention policy violations, and other compliance-related events. This building block rule generates security events for correlation, threat hunting, and telemetry collection without creating standalone alerts, reducing alert fatigue while maintaining comprehensive visibility into Microsoft Purview's compliance and security detections.

References #

AlertEntityGenerated

#
RecordType
SecurityComplianceAlerts

Description

An entity was added to a Microsoft 365 security/compliance alert generated by an alert policy in the Microsoft Defender / Purview portal.

Example Audit Record #

{
  "CreationTime": "2024-03-25T21:56:29",
  "Id": "bac7174a-19a9-4374-55fb-08dc4d166d45",
  "Operation": "AlertEntityGenerated",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 40,
  "ResultStatus": "Succeeded",
  "UserKey": "SecurityComplianceAlerts",
  "UserType": 4,
  "Version": 1,
  "Workload": "SecurityComplianceCenter",
  "ObjectId": "user15@splunkresearch.com",
  "UserId": "SecurityComplianceAlerts",
  "AlertEntityId": "user15@splunkresearch.com",
  "AlertId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
  "AlertLinks": [
    {
      "AlertLinkHref": ""
    }
  ],
  "AlertType": "System",
  "Category": "ThreatManagement",
  "Comments": "New alert",
  "Data": {
    "etype": "User",
    "eid": "user15@splunkresearch.com",
    "tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
    "ts": "2024-03-25T21:54:22.0000000Z",
    "te": "2024-03-25T21:54:22.0000000Z",
    "op": "MailRedirect",
    "tdc": "1",
    "suid": "user15@splunkresearch.com",
    "ut": "Regular",
    "ssic": "0",
    "lon": "MailRedirect"
  },
  "EntityType": "User",
  "Name": "Creation of forwarding/redirect rule",
  "PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
  "Severity": "Informational",
  "Source": "Office 365 Security & Compliance",
  "Status": "Active"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
RescanVerdict (splunk rule field)inmalware1 rulesplunk
RescanVerdict (splunk rule field)inphish1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Email Reported By User Found Malicious source: The following analytic detects when an email submitted to Microsoft using the built-in report button in Outlook is found to be malicious. This capability is an enhanced protection feature that can be used within o365 tenants by users to…T1566, T1566.001, T1566.002
  • O365 Email Suspicious Behavior Alert source: The following analytic identifies when one of O365 the built-in security detections for suspicious email behaviors are triggered. These alerts often indicate that an attacker may have compromised a mailbox within the environment. Any…T1114, T1114.003
  • O365 Safe Links Detection source: The following analytic detects when any Microsoft Safe Links alerting is triggered. This behavior may indicate when user has interacted with a phishing or otherwise malicious link within the Microsoft Office ecosystem.T1566, T1566.001

References #

AlertTriggered

#
RecordType
SecurityComplianceAlerts

Description

A Security & Compliance Center alert policy was triggered by activity matching the policy conditions.

Example Audit Record #

{
  "CreationTime": "2024-03-25T21:56:29",
  "Id": "95428ddb-9aa0-4bcf-84f4-08dc4d166d4c",
  "Operation": "AlertTriggered",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 40,
  "ResultStatus": "Succeeded",
  "UserKey": "SecurityComplianceAlerts",
  "UserType": 4,
  "Version": 1,
  "Workload": "SecurityComplianceCenter",
  "ObjectId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
  "UserId": "SecurityComplianceAlerts",
  "AlertId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
  "AlertLinks": [
    {
      "AlertLinkHref": ""
    }
  ],
  "AlertType": "System",
  "Category": "ThreatManagement",
  "Comments": "New alert",
  "Data": {
    "f3u": "user15@splunkresearch.com",
    "ts": "2024-03-25T21:54:00.0000000Z",
    "te": "2024-03-25T21:55:00.0000000Z",
    "op": "MailRedirect",
    "wl": "Exchange",
    "tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
    "tdc": "1",
    "reid": "136169be-3964-4b4c-2087-08dc4d1621a2",
    "wsrt": "2024-03-25T21:56:18",
    "mdt": "Audit",
    "rid": "0c04b79b-9148-4950-af22-2657dd53a92c",
    "cid": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
    "ad": "This alert is triggered when someone in your organization sets up auto-forwarding, email forwarding, redirect rule or a mail flow rule -V1.0.0.5",
    "lon": "MailRedirect",
    "an": "Creation of forwarding/redirect rule",
    "sev": "Informational"
  },
  "Name": "Creation of forwarding/redirect rule",
  "PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
  "Severity": "Informational",
  "Source": "Office 365 Security & Compliance",
  "Status": "Active"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Category (splunk rule field)eqthreatmanagement1 rulesplunk
Provider_Name (elastic rule field)eqsecuritycompliancecenter1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

References #

AlertUpdated

#
RecordType
SecurityComplianceAlerts

Description

The status or details of a Security and Compliance alert were updated (for example triage or resolution).

Example Audit Record #

{
  "CreationTime": "2024-03-25T21:54:15",
  "Id": "0d0eee3a-7bbe-005f-54eb-08dc4d161d48",
  "Operation": "AlertUpdated",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 40,
  "ResultStatus": "Succeeded",
  "UserKey": "SecurityComplianceAlerts",
  "UserType": 4,
  "Version": 1,
  "Workload": "SecurityComplianceCenter",
  "ObjectId": "95adeea5-ede1-136f-ae00-08dc4d156130",
  "UserId": "SecurityComplianceAlerts",
  "AlertId": "95adeea5-ede1-136f-ae00-08dc4d156130",
  "AlertLinks": [
    {
      "AlertLinkHref": ""
    }
  ],
  "AlertType": "System",
  "Category": "ThreatManagement",
  "Comments": "New alert",
  "Data": {
    "f3u": "user15@splunkresearch.com",
    "ts": "2024-03-25T21:48:00.0000000Z",
    "te": "2024-03-25T21:49:00.0000000Z",
    "op": "MailRedirect",
    "wl": "Exchange",
    "tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
    "tdc": "1",
    "reid": "884b4cf9-3329-47aa-7241-08dc4d1556b2",
    "wsrt": "2024-03-25T21:53:15",
    "mdt": "Audit",
    "rid": "0c04b79b-9148-4950-af22-2657dd53a92c",
    "cid": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
    "ad": "This alert is triggered when someone in your organization sets up auto-forwarding, email forwarding, redirect rule or a mail flow rule -V1.0.0.5",
    "lon": "MailRedirect",
    "an": "Creation of forwarding/redirect rule",
    "sev": "Informational"
  },
  "Name": "Creation of forwarding/redirect rule",
  "PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
  "Severity": "Informational",
  "Source": "Office 365 Security & Compliance",
  "Status": "Active"
}

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.