Wrangling the M365 UAL with PowerShell and SOF-ELK (Part 1 of 3)
ID: 01d7b037-b6fa-55df-bec6-7097b18818fb
STIX ID: report--01d7b037-b6fa-55df-bec6-7097b18818fb
Feed Name: Black Hills Infosec Blog
This post provides a practical guide to collecting and analyzing Microsoft 365 Unified Audit Log (UAL) data using the Exchange Online Management PowerShell module and the SOF-ELK stack, including environment setup, authentication, sample searches and filtering (operations and user agents), exporting results to JSON, a PowerShell script that queries in hourly increments to bypass the 5K-per-query limit, and steps to ingest and explore the data in SOF-ELK/Kibana for investigation workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
