1200KM / tag
m365 — logsource-product tag
17 related reference pages for logsource-product: m365.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Activity from Anonymous IP Addresses · sigma-rule
- Activity from Infrequent Country · sigma-rule
- Activity from Suspicious IP Addresses · sigma-rule
- Azure Login Bypassing Conditional Access Policies · sigma-rule
- Data Exfiltration to Unsanctioned Apps · sigma-rule
- Disabling Multi Factor Authentication · sigma-rule
- Logon from a Risky IP Address · sigma-rule
- Microsoft 365 - Impossible Travel Activity · sigma-rule
- Microsoft 365 - Potential Ransomware Activity · sigma-rule
- Microsoft 365 - Unusual Volume of File Deletion · sigma-rule
- Microsoft 365 - User Restricted from Sending Email · sigma-rule
- New Federated Domain Added · sigma-rule
- New Federated Domain Added - Exchange · sigma-rule
- PST Export Alert Using eDiscovery Alert · sigma-rule
- PST Export Alert Using New-ComplianceSearchAction · sigma-rule
- Suspicious Email Delivered In Microsoft 365 · sigma-rule
- Suspicious Inbox Forwarding · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.