Log sources › m365:signinlogs
m365:signinlogs
Inverted view: what can be detected if this is the log you have. Office Suite, SaaS
7
channels
9
analytics
8
techniques
2
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Sign-in from anomalous location or impossible travel condition |
DC0002 User Account Authentication | AN0338 | 1 |
Token usage events with device/user mismatch |
DC0067 Logon Session Creation | AN0723 | 1 |
Unusual sign-in from service principal to user mailbox |
DC0002 User Account Authentication | AN1107 | 1 |
UserLoggedIn |
DC0067 Logon Session Creation | AN1520 AN1565 AN1566 | 2 |
UserLogin |
DC0088 Logon Session Metadata | AN1506 | 1 |
UserLogin: Discovery operations shortly after account logins from new geolocations |
DC0067 Logon Session Creation | AN1129 | 1 |
UserLoginSuccess |
DC0002 User Account Authentication | AN0810 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1078.004 Cloud Accounts | stealth, persistence, privilege escalation, initial access | 41 | 1 |
| T1213.004 Customer Relationship Management Software | collection | 0 | 0 |
| T1213.005 Messaging Applications | collection | 0 | 0 |
| T1526 Cloud Service Discovery | discovery | 3 | 0 |
| T1531 Account Access Removal | impact | 9 | 1 |
| T1538 Cloud Service Dashboard | discovery | 0 | 0 |
| T1548.005 Temporary Elevated Cloud Access | privilege escalation | 0 | 0 |
| T1606 Forge Web Credentials | credential access | 1 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2023-34362 | Progress MOVEit Transfer | T1531 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1078.004 | Mapped |