Security & Compliance Center alert events
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-SecurityComplianceAlerts rules matching the RecordType but no specific Operation. | N | Y |
| Alert | An entity was added to a Microsoft 365 security/compliance alert generated by an alert policy in the Microsoft Defender / Purview portal. | Y | Y |
| Alert | A Security & Compliance Center alert policy was triggered by activity matching the policy conditions. | Y | Y |
| Alert | The status or details of a Security and Compliance alert were updated (for example triage or resolution). | Y | N |
any: Security & Compliance Center alert events (catch-all)
#Description
Catch-all for M365-SecurityComplianceAlerts rules matching the RecordType but no specific Operation.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name (elastic rule field) | eq | securitycompliancecenter | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
References #
AlertEntityGenerated
#Description
An entity was added to a Microsoft 365 security/compliance alert generated by an alert policy in the Microsoft Defender / Purview portal.
Example Audit Record #
{
"CreationTime": "2024-03-25T21:56:29",
"Id": "bac7174a-19a9-4374-55fb-08dc4d166d45",
"Operation": "AlertEntityGenerated",
"OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 40,
"ResultStatus": "Succeeded",
"UserKey": "SecurityComplianceAlerts",
"UserType": 4,
"Version": 1,
"Workload": "SecurityComplianceCenter",
"ObjectId": "user15@splunkresearch.com",
"UserId": "SecurityComplianceAlerts",
"AlertEntityId": "user15@splunkresearch.com",
"AlertId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
"AlertLinks": [
{
"AlertLinkHref": ""
}
],
"AlertType": "System",
"Category": "ThreatManagement",
"Comments": "New alert",
"Data": {
"etype": "User",
"eid": "user15@splunkresearch.com",
"tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"ts": "2024-03-25T21:54:22.0000000Z",
"te": "2024-03-25T21:54:22.0000000Z",
"op": "MailRedirect",
"tdc": "1",
"suid": "user15@splunkresearch.com",
"ut": "Regular",
"ssic": "0",
"lon": "MailRedirect"
},
"EntityType": "User",
"Name": "Creation of forwarding/redirect rule",
"PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
"Severity": "Informational",
"Source": "Office 365 Security & Compliance",
"Status": "Active"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
RescanVerdict (splunk rule field) | in | malware | 1 rule | splunk |
RescanVerdict (splunk rule field) | in | phish | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1566, T1566.001, T1566.002T1114, T1114.003T1566, T1566.001
References #
AlertTriggered
#Description
A Security & Compliance Center alert policy was triggered by activity matching the policy conditions.
Example Audit Record #
{
"CreationTime": "2024-03-25T21:56:29",
"Id": "95428ddb-9aa0-4bcf-84f4-08dc4d166d4c",
"Operation": "AlertTriggered",
"OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 40,
"ResultStatus": "Succeeded",
"UserKey": "SecurityComplianceAlerts",
"UserType": 4,
"Version": 1,
"Workload": "SecurityComplianceCenter",
"ObjectId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
"UserId": "SecurityComplianceAlerts",
"AlertId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
"AlertLinks": [
{
"AlertLinkHref": ""
}
],
"AlertType": "System",
"Category": "ThreatManagement",
"Comments": "New alert",
"Data": {
"f3u": "user15@splunkresearch.com",
"ts": "2024-03-25T21:54:00.0000000Z",
"te": "2024-03-25T21:55:00.0000000Z",
"op": "MailRedirect",
"wl": "Exchange",
"tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"tdc": "1",
"reid": "136169be-3964-4b4c-2087-08dc4d1621a2",
"wsrt": "2024-03-25T21:56:18",
"mdt": "Audit",
"rid": "0c04b79b-9148-4950-af22-2657dd53a92c",
"cid": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
"ad": "This alert is triggered when someone in your organization sets up auto-forwarding, email forwarding, redirect rule or a mail flow rule -V1.0.0.5",
"lon": "MailRedirect",
"an": "Creation of forwarding/redirect rule",
"sev": "Informational"
},
"Name": "Creation of forwarding/redirect rule",
"PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
"Severity": "Informational",
"Source": "Office 365 Security & Compliance",
"Status": "Active"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Category (splunk rule field) | eq | threatmanagement | 1 rule | splunk |
Provider_Name (elastic rule field) | eq | securitycompliancecenter | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1566, T1566.001, T1566.002Splunk #
o365_management_activity dataset, focusing on events where…T1078, T1078.004
References #
AlertUpdated
#Description
The status or details of a Security and Compliance alert were updated (for example triage or resolution).
Example Audit Record #
{
"CreationTime": "2024-03-25T21:54:15",
"Id": "0d0eee3a-7bbe-005f-54eb-08dc4d161d48",
"Operation": "AlertUpdated",
"OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"RecordType": 40,
"ResultStatus": "Succeeded",
"UserKey": "SecurityComplianceAlerts",
"UserType": 4,
"Version": 1,
"Workload": "SecurityComplianceCenter",
"ObjectId": "95adeea5-ede1-136f-ae00-08dc4d156130",
"UserId": "SecurityComplianceAlerts",
"AlertId": "95adeea5-ede1-136f-ae00-08dc4d156130",
"AlertLinks": [
{
"AlertLinkHref": ""
}
],
"AlertType": "System",
"Category": "ThreatManagement",
"Comments": "New alert",
"Data": {
"f3u": "user15@splunkresearch.com",
"ts": "2024-03-25T21:48:00.0000000Z",
"te": "2024-03-25T21:49:00.0000000Z",
"op": "MailRedirect",
"wl": "Exchange",
"tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"tdc": "1",
"reid": "884b4cf9-3329-47aa-7241-08dc4d1556b2",
"wsrt": "2024-03-25T21:53:15",
"mdt": "Audit",
"rid": "0c04b79b-9148-4950-af22-2657dd53a92c",
"cid": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
"ad": "This alert is triggered when someone in your organization sets up auto-forwarding, email forwarding, redirect rule or a mail flow rule -V1.0.0.5",
"lon": "MailRedirect",
"an": "Creation of forwarding/redirect rule",
"sev": "Informational"
},
"Name": "Creation of forwarding/redirect rule",
"PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
"Severity": "Informational",
"Source": "Office 365 Security & Compliance",
"Status": "Active"
}
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.