Elastic low stable kql
M365 Entra ID Risk Detection Signal
Identifies Microsoft Entra ID (formerly Azure AD) risk detection signals including risky sign-ins, compromised credentials, impossible travel, and other identity-based anomalies. These events indicate potential credential compromise, account takeover attempts, or suspicious authentication patterns detected by Microsoft's identity protection. This building block rule generates security events for correlation, threat hunting, and telemetry collection to support detection of credential access and initial access attempts.
Detection Logic
event.dataset:o365.audit and event.code:AadRiskDetection Field Validations
Loading…
Comments (0)
Loading comments...