Log sources › m365:unified
m365:unified
Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite, SaaS, Windows
86
channels
82
analytics
70
techniques
83
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Abnormal user claims or unexpected elevated role assignment in SAML assertion |
DC0088 Logon Session Metadata | AN0421 | 1 |
Accessed SharePoint files or pages |
DC0025 Cloud Storage Access | AN1160 | 1 |
Add app role assignment grant to user: Consent to application by privileged or unexpected accounts |
DC0066 Active Directory Object Modification | AN1487 | 1 |
Add member to group |
DC0094 Group Modification | AN0902 | 1 |
Add member to role, Set-Mailbox |
DC0010 User Account Modification | AN0773 | 1 |
Add user |
DC0014 User Account Creation | AN0902 | 1 |
Add-DelegatedAdmin, Set-PartnerOfRecord, Add-MailboxPermission, Set-OrganizationRelationship |
DC0038 Application Log Content | AN1350 | 1 |
Add-MailboxPermission or Set-ManagementRoleAssignment |
DC0038 Application Log Content | AN1107 | 1 |
Add-MailboxPermission, UpdateFolderPermissions |
DC0010 User Account Modification | AN1051 | 1 |
AddFlow / UpdateFlow: New automation or workflow creation events |
DC0069 Cloud Service Modification | AN1054 | 1 |
Admin Activity > Role Change or Sharing Change |
DC0010 User Account Modification | AN0270 | 1 |
AnonymousLinkCreated |
DC0027 Cloud Storage Metadata | AN1581 | 1 |
App-only or delegated access patterns where client_id != known enterprise apps |
DC0025 Cloud Storage Access | AN1426 | 1 |
Application Consent grants, new OAuth client registrations, or unusual admin-level activities executed by a user account shortly after suspected drive-by compromise |
DC0038 Application Log Content | AN0501 | 1 |
ApplicationModified, ConsentGranted: Unexpected app consent or modification events linked to security evasion |
DC0038 Application Log Content | AN1637 | 1 |
Automated forwarding or file sync initiated by a logic app |
DC0064 Command Execution | AN0028 | 1 |
Bulk downloads or API extractions from Microsoft-hosted data repositories (e.g., Dynamics 365) |
DC0055 File Access | AN0680 | 1 |
ConsentGranted: Abuse of application integrations to mint tokens bypassing MFA |
DC0038 Application Log Content | AN0496 | 1 |
Creation of Power Automate flow triggered by OneDrive or Exchange event |
DC0069 Cloud Service Modification | AN0028 | 1 |
Creation or modification of inbox rule outside of normal user behavior |
DC0038 Application Log Content | AN0264 | 1 |
Delegated permission grants without user login event |
DC0002 User Account Authentication | AN0527 | 1 |
Detection of hidden macro streams or SetHiddenAttribute actions |
DC0038 Application Log Content | AN1388 | 1 |
FileAccessed |
DC0038 Application Log Content | AN1581 | 1 |
FileAccessed, FileDownloaded, ConsentGranted |
DC0025 Cloud Storage Access | AN1329 | 1 |
FileAccessed, FileDownloaded, SearchQueried |
DC0038 Application Log Content | AN1380 | 1 |
FileAccessed, MailboxAccessed |
DC0055 File Access | AN0019 | 1 |
FileAccessed, SharingSet |
DC0088 Logon Session Metadata | AN1505 | 1 |
FileAccessed: Access of email attachments by Office applications |
DC0038 Application Log Content | AN0191 | 1 |
FileUploaded or FileCopied events |
DC0038 Application Log Content | AN1514 | 1 |
FileUploaded, FileAccessed |
DC0102 Network Share Access | AN1301 | 1 |
Folder configuration updated with external or HTML-formatted Home Page via Set-MailboxFolder |
DC0038 Application Log Content | AN0503 | 1 |
GAL Lookup or Address Book download |
DC0038 Application Log Content | AN0642 | 1 |
Get-MsolServicePrincipal, ListAppRoles: Service discovery operations executed by accounts not normally performing administrative tasks |
DC0083 Cloud Service Enumeration | AN1129 | 1 |
MacroSecuritySettingsChanged or SafeModeDisabled |
DC0063 Windows Registry Key Modification | AN0894 | 0 |
MailItemsAccessed; AddedInboxRule; ConsentToApplication; SharingSet |
DC0038 Application Log Content | AN2033 | 1 |
MailSend: Outlook messages with suspicious subject/body terms (e.g., urgent payment, wire transfer) targeting finance teams |
DC0038 Application Log Content | AN1365 | 1 |
MessageSend, MessageRead, or FileAttached events containing credential-like patterns |
DC0038 Application Log Content | AN0309 | 1 |
Modify Federation Settings or Update Authentication Policy |
DC0038 Application Log Content | AN0817 | 1 |
New agent registration by non-admin user |
DC0010 User Account Modification | AN0815 | 1 |
New-InboxRule or Set-InboxRule events recorded in Exchange Online |
DC0038 Application Log Content | AN0551 | 1 |
New-InboxRule, Set-InboxRule |
DC0070 Cloud Service Metadata | AN1591 | 1 |
Non-standard Office startup component detected (e.g., unexpected DLL path) |
DC0016 Module Load | AN0881 | 1 |
OAuthTokenIssued, FileAccessed, MailItemsAccessed |
DC0007 Web Credential Usage | AN0529 | 1 |
PowerShell: Add-MailboxPermission |
DC0038 Application Log Content | AN1052 | 1 |
PurgeAuditLogs, Remove-MailboxAuditLog |
DC0038 Application Log Content | AN0525 | 1 |
Read-only configuration review from GUI |
DC0038 Application Log Content | AN0810 | 1 |
Remove-Mailbox, Set-Mailbox |
DC0009 User Account Deletion | AN0338 | 1 |
RunMacro |
DC0038 Application Log Content | AN1405 | 1 |
Scripted Activity |
DC0029 Script Execution | AN1619 | 1 |
Search-Mailbox, Get-MessageTrace, eDiscovery requests |
DC0064 Command Execution | AN0132 | 1 |
Send/Receive: Emails with suspicious sender domains, spoofed headers, or anomalous attachment types |
DC0038 Application Log Content | AN0188 | 1 |
Send/Receive: Inbound emails containing embedded or shortened URLs |
DC0038 Application Log Content | AN0298 | 1 |
Send/Receive: Inbound emails with attachments from suspicious or spoofed senders |
DC0038 Application Log Content | AN0655 | 1 |
Send/Receive: Unusual spikes in inbound messages to a single recipient |
DC0038 Application Log Content | AN1008 | 1 |
SendMessage |
DC0069 Cloud Service Modification | AN0746 | 1 |
SendOnBehalf, MessageSend, AttachmentPreviewed |
DC0038 Application Log Content | AN0151 | 1 |
SendOnBehalf, MessageSend, ClickThrough, MailItemsAccessed |
DC0038 Application Log Content | AN0147 | 1 |
SendOnBehalf/SendAs: Emails sent where the sending identity mismatches account ownership |
DC0038 Application Log Content | AN0792 | 1 |
SendOnBehalf/SendAs: Office Suite initiated messages using impersonated identities |
DC0038 Application Log Content | AN0796 | 1 |
Session activity without correlated login event |
DC0007 Web Credential Usage | AN0487 | 1 |
Session creation without MFA or login event |
DC0006 Web Credential Creation | AN0722 | 1 |
SessionId reused from different device/browser fingerprint |
DC0007 Web Credential Usage | AN0202 | 1 |
Set federation settings on domain|Set domain authentication|Add federated identity provider |
DC0038 Application Log Content | AN0756 AN1260 | 2 |
Set-ADUser OR Set-ADAccountControl |
DC0010 User Account Modification | AN0290 | 1 |
Set-AdminAuditLogConfig;New-ApplicationAccessPolicy;ConsentToApplication |
DC0038 Application Log Content | AN2042 | 1 |
Set-CsOnlineUser or UpdateAuthPolicy |
DC0038 Application Log Content | AN0549 | 1 |
Set-Mailbox, Add-InboxRule, RegisterWebhook |
DC0038 Application Log Content | AN0440 | 1 |
Set-Mailbox, New-InboxRule |
DC0064 Command Execution | AN1312 | 1 |
Set-Mailbox, Set-AppPassword, Add-MailboxPermission |
DC0066 Active Directory Object Modification | AN1471 | 1 |
Set-Mailbox, Set-InboxRule, Set-MailboxFolderPermission |
DC0010 User Account Modification | AN1117 | 1 |
Set-Mailbox, Set-MailboxPolicy, Set-TrustedLocation |
DC0064 Command Execution | AN1437 | 1 |
Set-MailboxAuditBypassAssociation or disabling Advanced Auditing |
DC0010 User Account Modification | AN0803 | 1 |
Set-PartnerOfRecord / CompanyAdministrator role assignments / New-DelegatedAdminRelationship |
DC0038 Application Log Content | AN1347 | 1 |
SharingSet |
DC0023 Cloud Storage Modification | AN1581 | 1 |
Sign-in logs |
DC0002 User Account Authentication | AN1279 | 1 |
TeamsMessagesAccessedViaEDiscovery, TeamsGraphMessageExport |
DC0038 Application Log Content | AN1566 | 1 |
TokenIssued, FileAccessed |
DC0007 Web Credential Usage | AN0959 | 1 |
Transport rule or inbox rule creation events |
DC0038 Application Log Content | AN0554 | 1 |
Unusual MFA requests or OAuth consent events temporally aligned with user-reported vishing call |
DC0038 Application Log Content | AN0686 | 1 |
Unusual form activity within Outlook client, including load of non-default forms |
DC0038 Application Log Content | AN0086 | 1 |
User excluded from MFA or MFA method registered |
DC0010 User Account Modification | AN0544 | 1 |
UserLoggedIn |
DC0067 Logon Session Creation | AN0019 AN0203 | 2 |
ViewAdminReport |
DC0067 Logon Session Creation | AN0810 | 1 |
Workload=AzureActiveDirectory OR Exchange AND (Operation=Cmdlet AND Parameters contains 'Password' AND (CmdletName='Get-*' OR CmdletName='Get-OrganizationConfig')) |
DC0013 User Account Metadata | AN0460 | 1 |
certificate added or modified in application credentials |
DC0038 Application Log Content | AN0674 | 1 |
login using refresh_token with no preceding authentication context |
DC0002 User Account Authentication | AN0956 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-0767 | Adobe Flash Player | T1098 T1114.002 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2013-0640 | Adobe Reader and Acrobat | T1566.001 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1566.002 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1566.001 | Mapped |
| CVE-2017-11882 | Microsoft Office | T1566.001 | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1496 | Mapped |
| CVE-2018-11776 | Apache Struts | T1496 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1496 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1496 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1110 T1114 | Mapped |
| CVE-2020-12812 | Fortinet FortiOS | T1556 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1110 | Mapped |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1556 | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1496 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1496 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1496 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1098 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1496 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1566 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1496 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1087 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1070 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1211 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1212 | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1213 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1496 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1496 | Mapped |
| CVE-2022-34713 | Microsoft Windows | T1566 | Mapped |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service | T1566.001 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1087 T1567 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 T1566 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1070 T1496 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | T1496 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1530 | Stale |
| CVE-2023-2533 | PaperCut NG/MF | T1566.002 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1087 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1566.001 | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | T1496 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1531 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1213 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1566 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1496 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1496 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1496 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1566 T1567 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-21413 | Microsoft Office Outlook | T1566.002 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1496 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1114 T1566.002 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1528 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1114 T1566.002 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1530 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1078.004 T1199 T1212 | Mapped |
| CVE-2025-0411 | 7-Zip 7-Zip | T1566.001 | Mapped |
| CVE-2025-24054 | Microsoft Windows | T1566 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1566.001 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1496 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1212 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1212 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1567 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 | Mapped |