The Invisible Enemy: Unmasking Microsoft 365’s Logging Blind Spots
ID: d9745cd8-1f3f-5264-aba9-e5d37d22fad7
STIX ID: report--d9745cd8-1f3f-5264-aba9-e5d37d22fad7
Feed Name: Abstract Security Blog
This report examines blind spots in Microsoft 365 Management API and Microsoft Graph audit logs, validated through msInvader attack simulations, revealing that enumeration and many failed modification attempts are often unlogged while certain successful mailbox actions (e.g., inbox rule creation) and failed sign-ins are captured. It details discrepancies between M365 and Graph log formats, notes delays and event ordering issues, and provides detection guidance focused on what is reliably logged, chaining detections across attack steps, and leveraging enhanced Graph activity logging for improved visibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
