Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions rules/office365/o365-audit-log-purge.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Rule version v1.0.0

name: O365 Audit Log Purge
description: |
Detects attempts to purge, delete, or remove audit log data from Office 365.
Attackers commonly destroy audit evidence to cover their tracks after compromising
an environment. Detection of audit log deletion activities is a strong indicator
of an active adversary attempting to evade detection and hinder incident response.
category: "Defense Evasion"
technique: "T1070 - Indicator Removal"
references:
- "https://attack.mitre.org/techniques/T1070/"
dataTypes:
- o365
adversary: origin
impact:
confidentiality: 2
integrity: 3
availability: 0
where: oneOf("action", ["DSIPurgeStarted", "AuditSearchDeleted", "HardDelete"])
groupBy:
- adversary.user
Loading