kevmap

Log sources › m365:unified

m365:unified

Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite, SaaS, Windows

86
channels
82
analytics
70
techniques
83
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Abnormal user claims or unexpected elevated role assignment in SAML assertion DC0088 Logon Session Metadata AN0421 1
Accessed SharePoint files or pages DC0025 Cloud Storage Access AN1160 1
Add app role assignment grant to user: Consent to application by privileged or unexpected accounts DC0066 Active Directory Object Modification AN1487 1
Add member to group DC0094 Group Modification AN0902 1
Add member to role, Set-Mailbox DC0010 User Account Modification AN0773 1
Add user DC0014 User Account Creation AN0902 1
Add-DelegatedAdmin, Set-PartnerOfRecord, Add-MailboxPermission, Set-OrganizationRelationship DC0038 Application Log Content AN1350 1
Add-MailboxPermission or Set-ManagementRoleAssignment DC0038 Application Log Content AN1107 1
Add-MailboxPermission, UpdateFolderPermissions DC0010 User Account Modification AN1051 1
AddFlow / UpdateFlow: New automation or workflow creation events DC0069 Cloud Service Modification AN1054 1
Admin Activity > Role Change or Sharing Change DC0010 User Account Modification AN0270 1
AnonymousLinkCreated DC0027 Cloud Storage Metadata AN1581 1
App-only or delegated access patterns where client_id != known enterprise apps DC0025 Cloud Storage Access AN1426 1
Application Consent grants, new OAuth client registrations, or unusual admin-level activities executed by a user account shortly after suspected drive-by compromise DC0038 Application Log Content AN0501 1
ApplicationModified, ConsentGranted: Unexpected app consent or modification events linked to security evasion DC0038 Application Log Content AN1637 1
Automated forwarding or file sync initiated by a logic app DC0064 Command Execution AN0028 1
Bulk downloads or API extractions from Microsoft-hosted data repositories (e.g., Dynamics 365) DC0055 File Access AN0680 1
ConsentGranted: Abuse of application integrations to mint tokens bypassing MFA DC0038 Application Log Content AN0496 1
Creation of Power Automate flow triggered by OneDrive or Exchange event DC0069 Cloud Service Modification AN0028 1
Creation or modification of inbox rule outside of normal user behavior DC0038 Application Log Content AN0264 1
Delegated permission grants without user login event DC0002 User Account Authentication AN0527 1
Detection of hidden macro streams or SetHiddenAttribute actions DC0038 Application Log Content AN1388 1
FileAccessed DC0038 Application Log Content AN1581 1
FileAccessed, FileDownloaded, ConsentGranted DC0025 Cloud Storage Access AN1329 1
FileAccessed, FileDownloaded, SearchQueried DC0038 Application Log Content AN1380 1
FileAccessed, MailboxAccessed DC0055 File Access AN0019 1
FileAccessed, SharingSet DC0088 Logon Session Metadata AN1505 1
FileAccessed: Access of email attachments by Office applications DC0038 Application Log Content AN0191 1
FileUploaded or FileCopied events DC0038 Application Log Content AN1514 1
FileUploaded, FileAccessed DC0102 Network Share Access AN1301 1
Folder configuration updated with external or HTML-formatted Home Page via Set-MailboxFolder DC0038 Application Log Content AN0503 1
GAL Lookup or Address Book download DC0038 Application Log Content AN0642 1
Get-MsolServicePrincipal, ListAppRoles: Service discovery operations executed by accounts not normally performing administrative tasks DC0083 Cloud Service Enumeration AN1129 1
MacroSecuritySettingsChanged or SafeModeDisabled DC0063 Windows Registry Key Modification AN0894 0
MailItemsAccessed; AddedInboxRule; ConsentToApplication; SharingSet DC0038 Application Log Content AN2033 1
MailSend: Outlook messages with suspicious subject/body terms (e.g., urgent payment, wire transfer) targeting finance teams DC0038 Application Log Content AN1365 1
MessageSend, MessageRead, or FileAttached events containing credential-like patterns DC0038 Application Log Content AN0309 1
Modify Federation Settings or Update Authentication Policy DC0038 Application Log Content AN0817 1
New agent registration by non-admin user DC0010 User Account Modification AN0815 1
New-InboxRule or Set-InboxRule events recorded in Exchange Online DC0038 Application Log Content AN0551 1
New-InboxRule, Set-InboxRule DC0070 Cloud Service Metadata AN1591 1
Non-standard Office startup component detected (e.g., unexpected DLL path) DC0016 Module Load AN0881 1
OAuthTokenIssued, FileAccessed, MailItemsAccessed DC0007 Web Credential Usage AN0529 1
PowerShell: Add-MailboxPermission DC0038 Application Log Content AN1052 1
PurgeAuditLogs, Remove-MailboxAuditLog DC0038 Application Log Content AN0525 1
Read-only configuration review from GUI DC0038 Application Log Content AN0810 1
Remove-Mailbox, Set-Mailbox DC0009 User Account Deletion AN0338 1
RunMacro DC0038 Application Log Content AN1405 1
Scripted Activity DC0029 Script Execution AN1619 1
Search-Mailbox, Get-MessageTrace, eDiscovery requests DC0064 Command Execution AN0132 1
Send/Receive: Emails with suspicious sender domains, spoofed headers, or anomalous attachment types DC0038 Application Log Content AN0188 1
Send/Receive: Inbound emails containing embedded or shortened URLs DC0038 Application Log Content AN0298 1
Send/Receive: Inbound emails with attachments from suspicious or spoofed senders DC0038 Application Log Content AN0655 1
Send/Receive: Unusual spikes in inbound messages to a single recipient DC0038 Application Log Content AN1008 1
SendMessage DC0069 Cloud Service Modification AN0746 1
SendOnBehalf, MessageSend, AttachmentPreviewed DC0038 Application Log Content AN0151 1
SendOnBehalf, MessageSend, ClickThrough, MailItemsAccessed DC0038 Application Log Content AN0147 1
SendOnBehalf/SendAs: Emails sent where the sending identity mismatches account ownership DC0038 Application Log Content AN0792 1
SendOnBehalf/SendAs: Office Suite initiated messages using impersonated identities DC0038 Application Log Content AN0796 1
Session activity without correlated login event DC0007 Web Credential Usage AN0487 1
Session creation without MFA or login event DC0006 Web Credential Creation AN0722 1
SessionId reused from different device/browser fingerprint DC0007 Web Credential Usage AN0202 1
Set federation settings on domain|Set domain authentication|Add federated identity provider DC0038 Application Log Content AN0756 AN1260 2
Set-ADUser OR Set-ADAccountControl DC0010 User Account Modification AN0290 1
Set-AdminAuditLogConfig;New-ApplicationAccessPolicy;ConsentToApplication DC0038 Application Log Content AN2042 1
Set-CsOnlineUser or UpdateAuthPolicy DC0038 Application Log Content AN0549 1
Set-Mailbox, Add-InboxRule, RegisterWebhook DC0038 Application Log Content AN0440 1
Set-Mailbox, New-InboxRule DC0064 Command Execution AN1312 1
Set-Mailbox, Set-AppPassword, Add-MailboxPermission DC0066 Active Directory Object Modification AN1471 1
Set-Mailbox, Set-InboxRule, Set-MailboxFolderPermission DC0010 User Account Modification AN1117 1
Set-Mailbox, Set-MailboxPolicy, Set-TrustedLocation DC0064 Command Execution AN1437 1
Set-MailboxAuditBypassAssociation or disabling Advanced Auditing DC0010 User Account Modification AN0803 1
Set-PartnerOfRecord / CompanyAdministrator role assignments / New-DelegatedAdminRelationship DC0038 Application Log Content AN1347 1
SharingSet DC0023 Cloud Storage Modification AN1581 1
Sign-in logs DC0002 User Account Authentication AN1279 1
TeamsMessagesAccessedViaEDiscovery, TeamsGraphMessageExport DC0038 Application Log Content AN1566 1
TokenIssued, FileAccessed DC0007 Web Credential Usage AN0959 1
Transport rule or inbox rule creation events DC0038 Application Log Content AN0554 1
Unusual MFA requests or OAuth consent events temporally aligned with user-reported vishing call DC0038 Application Log Content AN0686 1
Unusual form activity within Outlook client, including load of non-default forms DC0038 Application Log Content AN0086 1
User excluded from MFA or MFA method registered DC0010 User Account Modification AN0544 1
UserLoggedIn DC0067 Logon Session Creation AN0019 AN0203 2
ViewAdminReport DC0067 Logon Session Creation AN0810 1
Workload=AzureActiveDirectory OR Exchange AND (Operation=Cmdlet AND Parameters contains 'Password' AND (CmdletName='Get-*' OR CmdletName='Get-OrganizationConfig')) DC0013 User Account Metadata AN0460 1
certificate added or modified in application credentials DC0038 Application Log Content AN0674 1
login using refresh_token with no preceding authentication context DC0002 User Account Authentication AN0956 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1021.007 Cloud Serviceslateral movement10
T1070 Indicator Removalstealth203
T1078.004 Cloud Accountsstealth, persistence, privilege escalation, initial access411
T1080 Taint Shared Contentlateral movement00
T1087 Account Discoverydiscovery166
T1087.003 Email Accountdiscovery00
T1098 Account Manipulationpersistence, privilege escalation342
T1098.001 Additional Cloud Credentialspersistence, privilege escalation30
T1098.002 Additional Email Delegate Permissionspersistence, privilege escalation00
T1098.003 Additional Cloud Rolespersistence, privilege escalation70
T1110 Brute Forcecredential access252
T1114 Email Collectioncollection43
T1114.002 Remote Email Collectioncollection01
T1114.003 Email Forwarding Rulecollection60
T1136.003 Cloud Accountpersistence30
T1137 Office Application Startuppersistence90
T1137.001 Office Template Macrospersistence00
T1137.002 Office Testpersistence20
T1137.003 Outlook Formspersistence10
T1137.004 Outlook Home Pagepersistence00
T1137.005 Outlook Rulespersistence00
T1189 Drive-by Compromiseinitial access321
T1199 Trusted Relationshipinitial access21
T1201 Password Policy Discoverydiscovery60
T1211 Exploitation for Stealthstealth41
T1212 Exploitation for Credential Accesscredential access54
T1213 Data from Information Repositoriescollection72
T1213.002 Sharepointcollection00
T1213.005 Messaging Applicationscollection00
T1213.006 Databasescollection00
T1484 Domain or Tenant Policy Modificationdefense impairment, privilege escalation10
T1484.002 Trust Modificationdefense impairment, privilege escalation20
T1496 Resource Hijackingimpact1319
T1526 Cloud Service Discoverydiscovery30
T1528 Steal Application Access Tokencredential access141
T1530 Data from Cloud Storagecollection02
T1531 Account Access Removalimpact91
T1534 Internal Spearphishinglateral movement00
T1537 Transfer Data to Cloud Accountexfiltration60
T1538 Cloud Service Dashboarddiscovery00
T1539 Steal Web Session Cookiecredential access20
T1546 Event Triggered Executionprivilege escalation, persistence100
T1548.005 Temporary Elevated Cloud Accessprivilege escalation00
T1550 Use Alternate Authentication Materiallateral movement50
T1550.001 Application Access Tokenlateral movement40
T1550.004 Web Session Cookielateral movement00
T1552.008 Chat Messagescredential access00
T1556 Modify Authentication Processdefense impairment, persistence, credential access122
T1556.006 Multi-Factor Authenticationdefense impairment, persistence, credential access30
T1556.007 Hybrid Identitydefense impairment, persistence, credential access00
T1564 Hide Artifactsstealth100
T1564.008 Email Hiding Rulesstealth40
T1566 Phishinginitial access146
T1566.001 Spearphishing Attachmentinitial access247
T1566.002 Spearphishing Linkinitial access45
T1566.004 Spearphishing Voiceinitial access00
T1567 Exfiltration Over Web Serviceexfiltration123
T1567.004 Exfiltration Over Webhookexfiltration00
T1606 Forge Web Credentialscredential access10
T1606.001 Web Cookiescredential access00
T1606.002 SAML Tokenscredential access00
T1648 Serverless Executionexecution00
T1649 Steal or Forge Authentication Certificatescredential access110
T1657 Financial Theftimpact00
T1667 Email Bombingimpact00
T1671 Cloud Application Integrationpersistence00
T1684 Social Engineeringstealth00
T1684.001 Impersonationstealth00
T1685.002 Disable or Modify Cloud Logdefense impairment30
T1687 Exploitation for Defense Impairmentdefense impairment00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2012-0767Adobe Flash Player T1098 T1114.002 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2013-0640Adobe Reader and Acrobat T1566.001 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 Mapped
CVE-2015-5119Adobe Flash Player T1566.002 Mapped
CVE-2015-8651Adobe Flash Player T1189 Mapped
CVE-2016-1019Adobe Flash Player T1189 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2017-11292Adobe Flash Player T1566.001 Mapped
CVE-2017-11882Microsoft Office T1566.001 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1496 Mapped
CVE-2018-11776Apache Struts T1496 Mapped
CVE-2018-7600Drupal Drupal Core T1496 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1496 Mapped
CVE-2020-0688Microsoft Exchange Server T1110 T1114 Mapped
CVE-2020-12812Fortinet FortiOS T1556 Mapped
CVE-2020-1472Microsoft Netlogon T1110 Mapped
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1556 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1496 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1496 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1496 Mapped
CVE-2021-32030ASUS Routers T1098 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1496 Mapped
CVE-2021-40449Microsoft Windows T1566 Mapped
CVE-2021-44228Apache Log4j2 T1496 Mapped
CVE-2021-44515Zoho Desktop Central T1087 Mapped
CVE-2021-45382D-Link Multiple Routers T1070 Mapped
CVE-2022-21999Microsoft Windows T1211 Mapped
CVE-2022-22948VMware vCenter Server T1212 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1213 Mapped
CVE-2022-29303SolarView Compact T1496 Mapped
CVE-2022-29464WSO2 Multiple Products T1496 Mapped
CVE-2022-34713Microsoft Windows T1566 Mapped
CVE-2022-41033Microsoft Windows COM+ Event System Service T1566.001 Mapped
CVE-2022-41082Microsoft Exchange Server T1087 T1567 Mapped
CVE-2022-41128Microsoft Windows T1070 T1566 Mapped
CVE-2023-1389TP-Link Archer AX21 T1070 T1496 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1496 Mapped
CVE-2023-22952SugarCRM Multiple Products T1530 Stale
CVE-2023-2533PaperCut NG/MF T1566.002 Mapped
CVE-2023-27532Veeam Backup & Replication T1087 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1566.001 Mapped
CVE-2023-32315Ignite Realtime Openfire T1496 Mapped
CVE-2023-34362Progress MOVEit Transfer T1531 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1213 Mapped
CVE-2023-36884Microsoft Windows T1566 Stale
CVE-2023-38035Ivanti Sentry T1496 Mapped
CVE-2023-43770Roundcube Webmail T1189 Mapped
CVE-2023-47565QNAP VioStor NVR T1496 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1496 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 Mapped
CVE-2024-11182MDaemon Email Server T1566 T1567 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-21413Microsoft Office Outlook T1566.002 Mapped
CVE-2024-23692Rejetto HTTP File Server T1496 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1114 T1566.002 Mapped
CVE-2024-38112Microsoft Windows T1189 Mapped
CVE-2024-38475Apache HTTP Server T1528 Mapped
CVE-2024-42009Roundcube Webmail T1114 T1566.002 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-49035Microsoft Partner Center T1530 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-5274Google Chromium V8 T1189 Mapped
CVE-2024-53704SonicWall SonicOS T1078.004 T1199 T1212 Mapped
CVE-2025-04117-Zip 7-Zip T1566.001 Mapped
CVE-2025-24054Microsoft Windows T1566 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-33053Microsoft Windows T1566.001 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1496 Mapped
CVE-2025-48927TeleMessage TM SGNL T1212 Mapped
CVE-2025-48928TeleMessage TM SGNL T1212 Mapped
CVE-2025-5419Google Chromium V8 T1189 Mapped
CVE-2025-54309CrushFTP CrushFTP T1567 Mapped
CVE-2025-6554Google Chromium V8 T1189 Mapped
CVE-2025-6558Google Chromium T1189 Mapped