Microsoft 365 Detection Pack
78 detection rules for the complete Microsoft 365 estate — Exchange Online, SharePoint, Teams, OneDrive, and M365 Defender. Business email compromise, insider threat, and ransomware precursor detections included.
Pack summary
- Detection rules
- 78
- Critical severity
- 22
- M365 services covered
- 6
- ATT&CK techniques
- 28
What's included
78 rules across 6 threat categories for the full M365 estate.
Forwarding rules, mailbox delegation, eDiscovery abuse, BCC transport rules, phishing delivery.
SharePoint mass download, OneDrive sync to unmanaged device, Power Automate data export.
High-severity Defender incidents correlated with raw audit events.
Admin role to guest, DLP policy disable, safe links bypass, audit log disabling.
SharePoint external links, Teams federation, external guest access without MFA.
Conditional Access exclusion additions, OWA re-enablement, impossible travel.
Detection rules (20 of 78 shown)
Showing 20 representative rules. All 78 rules activate with one click.
| Rule name | Severity |
|---|---|
| Exchange Online Mailbox Forwarding Rule Created to External Address | Critical |
| Exchange Online eDiscovery Search Run by Non-Compliance User | Critical |
| Exchange Online Mailbox Delegation Granted to Unusual User | High |
| SharePoint Mass File Download — Exfiltration Pattern | High |
| OneDrive Sync Client Enabled for Unmanaged Device | Medium |
| Teams External Access Enabled — Federated Domains | Medium |
| M365 Defender Incident — High Severity | Critical |
| Exchange Online Transport Rule Modified to BCC External Address | Critical |
| SharePoint Site Collection External Sharing Enabled | High |
| M365 Admin Role Assigned to Guest Account | Critical |
| M365 Compliance — DLP Policy Disabled | High |
| Exchange Online OWA Enabled for All Users After Being Disabled | High |
| M365 Unified Audit Log Disabled | Critical |
| Exchange Online Phishing Campaign Flagged by Defender | High |
| SharePoint Search API — Bulk Document Access Pattern | High |
| Exchange Online Safe Links Policy Disabled | High |
| Teams Guest Access Enabled Without MFA Requirement | Medium |
| M365 Power Automate Flow Created to Export Data | High |
| Exchange Online Anti-Spam Policy Modified | Medium |
| M365 Conditional Access Policy Exclusion Added | High |
Prerequisites
- Entra ID app registration with Office 365 Management APIs ActivityFeed.Read permission (application permission)
- M365 Unified Audit Log enabled (Admin Center > Compliance > Audit) — disabled by default in new tenants
- Microsoft 365 Defender API access for incident ingestion (securityAlerts.Read.All and ThreatHunting.Read.All)
- Exchange Online audit logging enabled per mailbox (Set-Mailbox -AuditEnabled $true) for mailbox-level events
Microsoft 365 Detection Pack: frequently asked questions
What M365 services does this detection pack cover?
The M365 detection pack covers Exchange Online (mail flow, forwarding, delegation), SharePoint Online (file access, external sharing, search API), OneDrive for Business (sync, sharing, downloads), Microsoft Teams (external federation, guest access, file sharing), Microsoft 365 Defender incidents, and the M365 Unified Audit Log. ManySignal connects via the Office 365 Management Activity API.
How does ManySignal ingest M365 audit logs?
ManySignal connects to the Office 365 Management Activity API using an Entra ID app registration with ActivityFeed.Read permission. Subscriptions are created for Audit.General, Audit.Exchange, Audit.SharePoint, and Audit.AzureActiveDirectory content types. ManySignal polls for new events at configurable intervals down to one minute.
Can ManySignal detect Business Email Compromise (BEC) patterns?
Yes. BEC detection covers the full attack chain: phishing delivery (Defender for Office 365 alerts), account compromise (Entra ID sign-in anomalies), mailbox forwarding rule creation (Exchange audit), eDiscovery abuse (compliance audit), and financial document access in SharePoint or OneDrive. Cross-product correlation is ManySignal's key advantage for BEC.
How does the pack handle Microsoft 365 Defender integration?
Microsoft 365 Defender incidents are ingested via the Defender API (securityAlerts.Read.All permission). Defender incidents are correlated with raw audit log events — a Defender phishing incident is enriched with the affected user's recent SharePoint download history, mailbox delegation changes, and sign-in anomalies.
Does this pack work with Microsoft 365 GCC High or DoD?
ManySignal supports Microsoft 365 Commercial, GCC, and GCC High endpoints. The Office 365 Management Activity API base URL and Entra ID authentication endpoints are configurable per environment. GCC High and DoD tenants require separate app registrations in the respective sovereign clouds.
Full Microsoft 365 threat coverage from Exchange to SharePoint
78 detection rules covering the complete M365 estate — from BEC forwarding rules to SharePoint mass download and M365 Defender correlation.