kevmap

TechniquesT1648 › AN1054

AN1054 Analytic 1054

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitor for creation of new Power Automate flows or equivalent automation scripts that trigger on user or file events. Detect anomalous actions performed by these automations, such as email forwarding, anonymous link creation, or unexpected API calls to external endpoints.</p>
Detects
T1648 Serverless Execution
Part of
DET0374 Detection Strategy for Serverless Execution (T1648)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedAddFlow / UpdateFlow: New automation or workflow creation eventsDC0069 Cloud Service Modification
m365:exchangeNew-InboxRule: Automation that triggers abnormal forwarding or external link generationDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
UserContextBusiness units or users where automation creation is expected (developers, admins)
FlowActionsSpecific automation actions (email forwarding, file sharing) that should be considered suspicious