Elastic low stable kql

M365 Entra ID Risk Detection Signal

Identifies Microsoft Entra ID (formerly Azure AD) risk detection signals including risky sign-ins, compromised credentials, impossible travel, and other identity-based anomalies. These events indicate potential credential compromise, account takeover attempts, or suspicious authentication patterns detected by Microsoft's identity protection. This building block rule generates security events for correlation, threat hunting, and telemetry collection to support detection of credential access and initial access attempts.

View Source

Detection Logic

event.dataset:o365.audit and event.code:AadRiskDetection

Field Validations

Loading…

Comments (0)

Loading comments...