Skip to content

Commit a1b6464

Browse files
authored
Merge pull request #944 from nterl0k/nterl0k-t1114.003-transport-rule-change
Nterl0k - T1114.003 O365 Transport Rule Changes
2 parents ece6fba + c54d3b7 commit a1b6464

File tree

2 files changed

+16
-0
lines changed

2 files changed

+16
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:1520bac551d6b6d79dc2326e444f7414166d3706fdf6dc2a4ab8c701c317d292
3+
size 3113
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Steven Dick
2+
id: 3528c82a-ac25-4d88-b877-7c067f3a3710
3+
date: '2025-01-15'
4+
description: 'Sample of events when an Exchange transport rule is created or modified.'
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114.003/transport_rule_change/transport_rule_change.log
8+
sourcetypes:
9+
- o365:management:activity
10+
references:
11+
- https://attack.mitre.org/techniques/T1114/003/
12+
- https://cardinalops.com/blog/cardinalops-contributes-new-mitre-attck-techniques-related-to-abuse-of-mail-transport-rules/
13+
- https://www.microsoft.com/en-us/security/blog/2022/09/22/malicious-OAuth-applications-used-to-compromise-email-servers-and-spread-spam/

0 commit comments

Comments
 (0)