Log sources › m365:defender
m365:defender
Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite, Windows
4
channels
4
analytics
4
techniques
14
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Activity Log: Command Invocation |
DC0064 Command Execution | AN1087 | 1 |
NetworkConnection: high out:in ratio, periodic beacons, protocol mismatch |
DC0078 Network Traffic Flow | AN0927 | 1 |
OfficeTelemetry or DLP |
DC0061 File Modification | AN1302 | 1 |
ScriptBlockLogging + AMSI |
DC0029 Script Execution | AN0733 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1059.007 JavaScript | execution | 29 | 14 |
| T1080 Taint Shared Content | lateral movement | 0 | 0 |
| T1087.004 Cloud Account | discovery | 3 | 0 |
| T1132.002 Non-Standard Encoding | command and control | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2013-3346 | Adobe Reader and Acrobat | T1059.007 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1059.007 | Mapped |
| CVE-2018-4990 | Adobe Acrobat and Reader | T1059.007 | Mapped |
| CVE-2021-21148 | Google Chromium V8 | T1059.007 | Mapped |
| CVE-2021-21166 | Google Chromium | T1059.007 | Mapped |
| CVE-2021-21206 | Google Chromium Blink | T1059.007 | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | T1059.007 | Mapped |
| CVE-2021-37975 | Google Chromium V8 | T1059.007 | Mapped |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | T1059.007 | Mapped |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) | T1059.007 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1059.007 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1059.007 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1059.007 | Mapped |
| CVE-2025-34028 | Commvault Command Center | T1059.007 | Mapped |