kevmap

Log sources › m365:signinlogs

m365:signinlogs

Inverted view: what can be detected if this is the log you have. Office Suite, SaaS

7
channels
9
analytics
8
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Sign-in from anomalous location or impossible travel condition DC0002 User Account Authentication AN0338 1
Token usage events with device/user mismatch DC0067 Logon Session Creation AN0723 1
Unusual sign-in from service principal to user mailbox DC0002 User Account Authentication AN1107 1
UserLoggedIn DC0067 Logon Session Creation AN1520 AN1565 AN1566 2
UserLogin DC0088 Logon Session Metadata AN1506 1
UserLogin: Discovery operations shortly after account logins from new geolocations DC0067 Logon Session Creation AN1129 1
UserLoginSuccess DC0002 User Account Authentication AN0810 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1078.004 Cloud Accountsstealth, persistence, privilege escalation, initial access411
T1213.004 Customer Relationship Management Softwarecollection00
T1213.005 Messaging Applicationscollection00
T1526 Cloud Service Discoverydiscovery30
T1531 Account Access Removalimpact91
T1538 Cloud Service Dashboarddiscovery00
T1548.005 Temporary Elevated Cloud Accessprivilege escalation00
T1606 Forge Web Credentialscredential access10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2023-34362Progress MOVEit Transfer T1531 Mapped
CVE-2024-53704SonicWall SonicOS T1078.004 Mapped