M ManySignal
Detection Pack Microsoft 365

Microsoft 365 Detection Pack

78 detection rules for the complete Microsoft 365 estate — Exchange Online, SharePoint, Teams, OneDrive, and M365 Defender. Business email compromise, insider threat, and ransomware precursor detections included.

Pack summary

Detection rules
78
Critical severity
22
M365 services covered
6
ATT&CK techniques
28

What's included

78 rules across 6 threat categories for the full M365 estate.

Business Email Compromise 22 rules

Forwarding rules, mailbox delegation, eDiscovery abuse, BCC transport rules, phishing delivery.

Data Exfiltration 20 rules

SharePoint mass download, OneDrive sync to unmanaged device, Power Automate data export.

M365 Defender Alerts 14 rules

High-severity Defender incidents correlated with raw audit events.

Admin & Policy Abuse 12 rules

Admin role to guest, DLP policy disable, safe links bypass, audit log disabling.

External Sharing & Federation 6 rules

SharePoint external links, Teams federation, external guest access without MFA.

Identity Threats 4 rules

Conditional Access exclusion additions, OWA re-enablement, impossible travel.

Detection rules (20 of 78 shown)

Showing 20 representative rules. All 78 rules activate with one click.

Rule name Severity
Exchange Online Mailbox Forwarding Rule Created to External Address Critical
Exchange Online eDiscovery Search Run by Non-Compliance User Critical
Exchange Online Mailbox Delegation Granted to Unusual User High
SharePoint Mass File Download — Exfiltration Pattern High
OneDrive Sync Client Enabled for Unmanaged Device Medium
Teams External Access Enabled — Federated Domains Medium
M365 Defender Incident — High Severity Critical
Exchange Online Transport Rule Modified to BCC External Address Critical
SharePoint Site Collection External Sharing Enabled High
M365 Admin Role Assigned to Guest Account Critical
M365 Compliance — DLP Policy Disabled High
Exchange Online OWA Enabled for All Users After Being Disabled High
M365 Unified Audit Log Disabled Critical
Exchange Online Phishing Campaign Flagged by Defender High
SharePoint Search API — Bulk Document Access Pattern High
Exchange Online Safe Links Policy Disabled High
Teams Guest Access Enabled Without MFA Requirement Medium
M365 Power Automate Flow Created to Export Data High
Exchange Online Anti-Spam Policy Modified Medium
M365 Conditional Access Policy Exclusion Added High

Prerequisites

  • Entra ID app registration with Office 365 Management APIs ActivityFeed.Read permission (application permission)
  • M365 Unified Audit Log enabled (Admin Center > Compliance > Audit) — disabled by default in new tenants
  • Microsoft 365 Defender API access for incident ingestion (securityAlerts.Read.All and ThreatHunting.Read.All)
  • Exchange Online audit logging enabled per mailbox (Set-Mailbox -AuditEnabled $true) for mailbox-level events

Microsoft 365 Detection Pack: frequently asked questions

What M365 services does this detection pack cover?

The M365 detection pack covers Exchange Online (mail flow, forwarding, delegation), SharePoint Online (file access, external sharing, search API), OneDrive for Business (sync, sharing, downloads), Microsoft Teams (external federation, guest access, file sharing), Microsoft 365 Defender incidents, and the M365 Unified Audit Log. ManySignal connects via the Office 365 Management Activity API.

How does ManySignal ingest M365 audit logs?

ManySignal connects to the Office 365 Management Activity API using an Entra ID app registration with ActivityFeed.Read permission. Subscriptions are created for Audit.General, Audit.Exchange, Audit.SharePoint, and Audit.AzureActiveDirectory content types. ManySignal polls for new events at configurable intervals down to one minute.

Can ManySignal detect Business Email Compromise (BEC) patterns?

Yes. BEC detection covers the full attack chain: phishing delivery (Defender for Office 365 alerts), account compromise (Entra ID sign-in anomalies), mailbox forwarding rule creation (Exchange audit), eDiscovery abuse (compliance audit), and financial document access in SharePoint or OneDrive. Cross-product correlation is ManySignal's key advantage for BEC.

How does the pack handle Microsoft 365 Defender integration?

Microsoft 365 Defender incidents are ingested via the Defender API (securityAlerts.Read.All permission). Defender incidents are correlated with raw audit log events — a Defender phishing incident is enriched with the affected user's recent SharePoint download history, mailbox delegation changes, and sign-in anomalies.

Does this pack work with Microsoft 365 GCC High or DoD?

ManySignal supports Microsoft 365 Commercial, GCC, and GCC High endpoints. The Office 365 Management Activity API base URL and Entra ID authentication endpoints are configurable per environment. GCC High and DoD tenants require separate app registrations in the respective sovereign clouds.

Full Microsoft 365 threat coverage from Exchange to SharePoint

78 detection rules covering the complete M365 estate — from BEC forwarding rules to SharePoint mass download and M365 Defender correlation.