Skip to content

Commit

Permalink
Merge pull request #11755 from Azure/shainw-fixMailItemsUrl
Browse files Browse the repository at this point in the history
Update MailItemsAccessedTimeSeries.yaml
  • Loading branch information
ashwin-patil authored Feb 3, 2025
2 parents 03d2380 + 750d63d commit 939d1bd
Showing 1 changed file with 3 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ description: |
The query leverages KQL built-in anomaly detection algorithms to find large deviations from baseline patterns.
Sudden increases in execution frequency of sensitive actions should be further investigated for malicious activity.
Manually change scorethreshold from 1.5 to 3 or higher to reduce the noise based on outliers flagged from the query criteria.
Read more about MailItemsAccessed- https://docs.microsoft.com/microsoft-365/compliance/advanced-audit?view=o365-worldwide#mailitemsaccessed'
Read more about MailItemsAccessed- https://learn.microsoft.com/en-us/purview/audit-log-investigate-accounts'
severity: Medium
status: Available
requiredDataConnectors:
Expand Down Expand Up @@ -76,5 +76,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: SourceIPMax
version: 2.0.5
kind: Scheduled
version: 2.0.6
kind: Scheduled

0 comments on commit 939d1bd

Please sign in to comment.