New Location Sign in with Mail forwarding activity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query helps detect new Microsoft Entra ID sign in from a new location correlating with Office Activity data highlighting cases where user mails are being forwarded and shows if it is being forwarded to external domains as well.

Attribute Value
Type Hunting Query
Solution GitHub Only
ID a689a21c-9369-47e6-b5fa-e1f65045c1cf
Tactics Collection, Exfiltration, InitialAccess
Techniques T1114, T1020, T1078
Required Connectors Office365, AzureActiveDirectory
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/MultipleDataSources/MailForwardingActivityFromNewLocation.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries