Public reference

Detection Logic Catalog

This page documents all current ITDR built-in detections from the live rule engine so your incident response team can review trigger logic, thresholds, grouping, and evidence expectations.

Total rules: 28Directory audit: 5Sign-in: 11O365 Mgmt: 4Attack chain: 8

View mode

Executive mode highlights business impact, priority, and remediation guidance.

Detection coverage model

Rule behavior is validated against live Microsoft telemetry, then alerts are grouped into incidents through the same investigation workflow used in the platform.

Office 365 Management telemetry supports both native mailbox-rule detections and mapped SecurityCompliance/threat signals.

Office 365 Management coverage model

This catalog includes built-in Exchange mailbox-rule detections. In addition, the platform ingests Office 365 Management content types (`Audit.AzureActiveDirectory`, `Audit.Exchange`, `Audit.SharePoint`, `Audit.General`, `DLP.All`) and maps SecurityCompliance/threat-related records into alerts with source `o365_management`.

Subscription-level failures are warning-classified. If one content type is unavailable (for example `DLP.All`), other enabled content types can still ingest.

Licensing realism

This matrix reflects current platform behavior and production observations as of April 22, 2026. Microsoft licensing and tenant entitlements can change; this page is an operational guide, not a legal licensing contract.

Microsoft references: Business Premium security overview | Entra risk detection licensing | Entra log retention by tier

Operational expectations

Prevent vs detect vs contain (realistic positioning)

Prevent initial login

Identity platform controls

Conditional Access, phishing-resistant auth, device compliance, and browser/DNS controls stop many attacks before account session establishment.

Detect compromise patterns

ITDR detections (this catalog)

The rules on this page detect suspicious identity and workload behavior from Graph telemetry and correlated context; provider-originated Office 365 alerts are mapped separately.

Contain and respond

Platform response workflow

Capability-aware actions, verification, and immutable action history reduce dwell time after a suspicious event is observed.

Latency reality: detection speed depends on Microsoft log publication and ingestion windows. ITDR can be fast after events are queryable, but it is not an inline authentication gate.

Executive detection view

Risk outcomes, plain-English triggers, and references

Critical/high firstWho/what/when/where in product queues

Priority model

Detections are score-driven. Higher scores represent higher response urgency and should be triaged first.

Business value

Focuses SOC effort on likely compromise patterns and concrete containment paths instead of raw event volume.

Operational caveat

Detection timing still depends on Microsoft log publication latency and connector health.

Severity
Family

28 rules

1. High-risk app permission or governance change

Inspect directory audit events and match sensitive governance keywords.

highdirectory audit
Impact: Governance or permission change with identity-control impact. Review ownership and approval context quickly.
T1098 Account ManipulationT1528 Steal Application Access Token

- Review audit event and approval context.

- Inspect workload permissions and linked posture findings.

3. Ownerless privileged workload identity change

Start from sensitive audit candidates.

criticaldirectory audit
Impact: Governance or permission change with identity-control impact. Review ownership and approval context quickly.
T1098 Account ManipulationT1528 Steal Application Access Token

- Assign accountable owner(s) immediately.

- Rotate credentials and remove unneeded high-risk permissions.

4. Possible rogue application consent burst

Group consent/grant keyword events per entity (application or service principal).

highdirectory audit
Impact: Governance or permission change with identity-control impact. Review ownership and approval context quickly.
T1098 Account ManipulationT1528 Steal Application Access Token

- Validate all grants/consents in the burst.

- Remove unauthorized delegated/app permissions.

27. Workload app retrying with expired client secret

Group service principal sign-in events by app_id.

mediumsign in
Impact: Identity sign-in anomaly that may indicate credential theft, session abuse, or malicious automation.
T1078 Valid AccountsT1110 Brute Force

- Confirm with the application owner whether this integration is still in use.

- If in use, rotate the expired client secret in the Azure AD app registration and update the application configuration.

28. Adversary-in-the-middle token replay from distinct device

Pair each successful INTERACTIVE sign-in with successful NON-INTERACTIVE sign-ins for the same identity within the next 30 minutes.

highsign in
Impact: Identity sign-in anomaly that may indicate credential theft, session abuse, or malicious automation.
T1078 Valid AccountsT1110 Brute Force

- Revoke active sessions for the identity to invalidate any captured tokens.

- Reset the user's password and require re-registration of MFA methods.

11. Credential theft pattern across identities

Group failed sign-ins by public source IP address.

highsign in
Impact: Identity sign-in anomaly that may indicate credential theft, session abuse, or malicious automation.
T1078 Valid AccountsT1110 Brute Force

- Treat as password spray or credential stuffing until disproven.

- Block/challenge source IP and validate conditional access behavior.

12. Malicious datacenter utilization pattern

Group successful sign-ins by public source IP address.

highsign in
Impact: Identity sign-in anomaly that may indicate credential theft, session abuse, or malicious automation.
T1078 Valid AccountsT1110 Brute Force

- Validate whether the source infrastructure is approved.

- Investigate affected users for token misuse or session theft patterns.

13. Malicious Inbox Rule Detection

Inspect Office 365 Management Exchange events for inbox-rule operations.

higho365 management
Impact: Mailbox persistence or suppression pattern. Validate account takeover risk and potential business-email impact.
T1114 Email CollectionT1564 Hide Artifacts

- Review and disable suspicious inbox rules.

- Inspect forwarding/redirect settings and mailbox access history.

14. Suspicious Email Filter Hiding Generic Account and Security Notifications

Start from suspicious Exchange inbox-rule manipulation.

higho365 management
Impact: Mailbox persistence or suppression pattern. Validate account takeover risk and potential business-email impact.
T1114 Email CollectionT1564 Hide Artifacts

- Remove or disable suspicious mailbox filter rules immediately.

- Validate whether user received/acted on concurrent phishing content.

15. Suspicious Email Filter Hiding Finance and BEC Keywords

Start from suspicious Exchange inbox-rule manipulation.

criticalo365 management
Impact: Mailbox persistence or suppression pattern. Validate account takeover risk and potential business-email impact.
T1114 Email CollectionT1564 Hide Artifacts

- Treat as potential active BEC attempt and isolate mailbox quickly.

- Review recent sent/forwarded/deleted finance communications.

16. Suspicious Email Filter Hiding External Account Security Notifications

Start from suspicious Exchange inbox-rule manipulation.

higho365 management
Impact: Mailbox persistence or suppression pattern. Validate account takeover risk and potential business-email impact.
T1114 Email CollectionT1564 Hide Artifacts

- Remove suspicious rules and inspect account for phishing foothold indicators.

- Check for linked identity changes and suspicious OAuth grants.

17. Attack chain: risky login to MFA change to inbox rule

Correlate risky sign-in detection with authentication-method change event on same identity.

criticalattack chain
Impact: High-confidence compromise storyline. Prioritize immediate analyst triage and containment readiness.
Multi-stage CorrelationT1098 Account Manipulation

- Contain identity immediately (revoke sessions, reset credentials, validate MFA methods).

- Remove mailbox persistence and investigate scope of compromise.

18. Attack chain: password spray to success to lateral movement

Start from credential theft spray alert keyed to source IP.

criticalattack chain
Impact: High-confidence compromise storyline. Prioritize immediate analyst triage and containment readiness.
Multi-stage Correlation

- Block/challenge source infrastructure and enforce step-up controls.

- Contain impacted identities and review additional persistence attempts.

19. Attack chain: token replay across multiple identities

Aggregate non-interactive token replay alerts by shared source IP.

highattack chain
Impact: High-confidence compromise storyline. Prioritize immediate analyst triage and containment readiness.
Multi-stage Correlation

- Treat as possible token theft campaign spanning multiple identities.

- Revoke active sessions/tokens across affected identities.

20. MFA denied challenge followed by successful sign-in

Start from successful sign-ins and look back for prior failures on the same identity and app context.

highsign in
Impact: Identity sign-in anomaly that may indicate credential theft, session abuse, or malicious automation.
T1078 Valid AccountsT1110 Brute ForceT1098 Account Manipulation

- Treat this as potential MFA push-fatigue/challenge manipulation until user intent is verified.

- Revoke sessions and require reauthentication if legitimacy is unclear.

21. Authentication method change after risky sign-in

Start from risky successful sign-in detections for an identity.

highattack chain
Impact: High-confidence compromise storyline. Prioritize immediate analyst triage and containment readiness.
Multi-stage Correlation

- Validate whether the authentication-method change was expected and approved by the user.

- Revoke sessions and reset credentials if sign-in legitimacy is uncertain.

22. Password reset after risky sign-in

Start from risky successful sign-in detections for an identity.

highattack chain
Impact: High-confidence compromise storyline. Prioritize immediate analyst triage and containment readiness.
Multi-stage CorrelationT1098 Account Manipulation

- Validate whether the password reset/change was initiated by the legitimate user.

- Revoke sessions and force secure credential reset if legitimacy is uncertain.

23. OAuth consent activity after risky sign-in

Start from risky successful sign-in detections for an identity.

highattack chain
Impact: High-confidence compromise storyline. Prioritize immediate analyst triage and containment readiness.
Multi-stage Correlation

- Validate whether the OAuth consent or permission grant was explicitly approved.

- Revoke unauthorized delegated/app grants and disable suspicious workload identities.

24. MFA method weakened after risky sign-in

Start from risky successful sign-in detections for an identity.

criticalattack chain
Impact: High-confidence compromise storyline. Prioritize immediate analyst triage and containment readiness.
Multi-stage CorrelationT1098 Account Manipulation

- Treat as potential MFA-bypass persistence and validate user intent immediately.

- Revoke sessions and require strong MFA method re-registration.

25. Privileged role assignment by risky actor

Start from risky successful sign-in detections for an identity.

criticalattack chain
Impact: High-confidence compromise storyline. Prioritize immediate analyst triage and containment readiness.
Multi-stage CorrelationT1078.004 Cloud Accounts

- Revoke newly assigned privileged roles until approval context is confirmed.

- Contain actor identity and invalidate active sessions/tokens.

26. Likely dormant workload identity suddenly active

Evaluate older workload identities (service principals) for newly observed recent sign-in activity.

highdirectory audit
Impact: Governance or permission change with identity-control impact. Review ownership and approval context quickly.
T1098 Account ManipulationT1528 Steal Application Access Token

- Validate ownership/business intent for this workload identity activation.

- Review and roll back unauthorized credential/permission changes.

Go to sign inPlatform value overviewWhy we built ITDRDetection validationLicense coverageFAQ