| Abnormal Authentication & Access | app-activity ↳microsoft-exchange-json-email-receive-incoming ↳microsoft-exchange-csv-app-notification-hadiscard ↳microsoft-exchange-csv-app-notification-agentresubmit ↳microsoft-exchange-csv-app-notification-agentdefer ↳microsoft-exchange-csv-app-notification-agentinfo ↳microsoft-exchange-csv-app-notification-routingexpand ↳microsoft-exchange-csv-app-notification-routingtransfer ↳microsoft-exchange-csv-app-notification-processmeetingmessage ↳microsoft-exchange-csv-app-notification-success-smtpfail ↳microsoft-exchange-csv-app-notification-routingdrop ↳microsoft-exchange-csv-app-notification-dsn ↳microsoft-exchange-csv-app-notification-routing ↳microsoft-exchange-csv-app-notification-routingduplicateredirect ↳microsoft-exchange-csv-app-notification-transfer ↳microsoft-exchange-csv-app-notification-success-storedriver ↳microsoft-exchange-csv-app-notification-redirecting ↳microsoft-exchange-csv-app-notification-smtpharedirect ↳microsoft-exchange-csv-app-notification-success-safetynetresubmit ↳microsoft-exchange-csv-app-notification-smtpharedirectfail ↳microsoft-exchange-csv-app-notification-smtpdefer ↳microsoft-exchange-csv-app-notification-success-queuetransfer ↳microsoft-exchange-csv-app-notification-success-routingsuppressed ↳microsoft-exchange-csv-app-notification-success-queueresubmit ↳microsoft-exchange-str-app-activity-success-isaweblog ↳microsoft-o365-cef-app-file-success-modifiedproperties ↳microsoft-o365-sk4-app-activity-success-softdelete ↳microsoft-exchange-sk4-app-activity-success-harddelete ↳microsoft-o365-cef-app-file-success-modifiedproperties
app-login ↳microsoft-exchange-csv-app-authentication-success-server ↳microsoft-exchange-kv-app-login-success-serverexchange
authentication-successful ↳microsoft-exchange-kv-app-authentication-success-exserver
| T1078 - Valid Accounts T1133 - External Remote Services
| |
| Account Manipulation | app-activity ↳microsoft-exchange-json-email-receive-incoming ↳microsoft-exchange-csv-app-notification-hadiscard ↳microsoft-exchange-csv-app-notification-agentresubmit ↳microsoft-exchange-csv-app-notification-agentdefer ↳microsoft-exchange-csv-app-notification-agentinfo ↳microsoft-exchange-csv-app-notification-routingexpand ↳microsoft-exchange-csv-app-notification-routingtransfer ↳microsoft-exchange-csv-app-notification-processmeetingmessage ↳microsoft-exchange-csv-app-notification-success-smtpfail ↳microsoft-exchange-csv-app-notification-routingdrop ↳microsoft-exchange-csv-app-notification-dsn ↳microsoft-exchange-csv-app-notification-routing ↳microsoft-exchange-csv-app-notification-routingduplicateredirect ↳microsoft-exchange-csv-app-notification-transfer ↳microsoft-exchange-csv-app-notification-success-storedriver ↳microsoft-exchange-csv-app-notification-redirecting ↳microsoft-exchange-csv-app-notification-smtpharedirect ↳microsoft-exchange-csv-app-notification-success-safetynetresubmit ↳microsoft-exchange-csv-app-notification-smtpharedirectfail ↳microsoft-exchange-csv-app-notification-smtpdefer ↳microsoft-exchange-csv-app-notification-success-queuetransfer ↳microsoft-exchange-csv-app-notification-success-routingsuppressed ↳microsoft-exchange-csv-app-notification-success-queueresubmit ↳microsoft-exchange-str-app-activity-success-isaweblog ↳microsoft-o365-cef-app-file-success-modifiedproperties ↳microsoft-o365-sk4-app-activity-success-softdelete ↳microsoft-exchange-sk4-app-activity-success-harddelete ↳microsoft-o365-cef-app-file-success-modifiedproperties
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
| |
| Ransomware | app-login ↳microsoft-exchange-csv-app-authentication-success-server ↳microsoft-exchange-kv-app-login-success-serverexchange
authentication-successful ↳microsoft-exchange-kv-app-authentication-success-exserver
| T1078 - Valid Accounts
| |
| Next Page -->> | | | |