Loading

M365 Quarantine and Hygiene Signal

Identifies Microsoft 365 email quarantine, hygiene, and mail submission events. These signals indicate blocked threats, spam filtering actions, and user-reported suspicious emails. While these represent blocked or mitigated threats, they provide valuable telemetry for understanding attempted attacks and attack patterns. This building block rule generates security events for correlation, threat hunting, and telemetry collection.

Rule type: query
Rule indices:

  • logs-o365.audit-*
  • filebeat-*

Rule Severity: low
Risk Score: 21
Runs every:
Searches indices from: now-9m
Maximum alerts per execution: 100
References:

Tags:

  • Domain: Cloud
  • Domain: SaaS
  • Data Source: Microsoft 365
  • Data Source: Microsoft 365 Audit Logs
  • Data Source: Microsoft Defender for Office 365
  • Use Case: Threat Detection
  • Use Case: Blocked Threat Tracking
  • Tactic: Initial Access
  • Rule Type: BBR

Version: 1
Rule authors:

  • Elastic

Rule license: Elastic License v2

For information on troubleshooting the maximum alerts warning please refer to this guide.

event.dataset:o365.audit and event.code:(Quarantine or HygieneEvent or MailSubmission)
		

Framework: MITRE ATT&CK