Analyzing Office365 Audit Logs For Compromise

Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.

theheavenlyd3mon a57ecc2 4 files · 25.6 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-forensics/skills/Anthropic-Cybersecurity-Skills/skills/analyzing-office365-audit-logs-for-compromise commit a57ecc2650

Frequently asked questions

npx skillmds add theheavenlyd3mon/analyzing-office365-audit-logs-for-compromise