logo

New Microsoft Incident Response guides help security teams analyze suspicious activity

ID: 7bf1d13e-332a-5b4a-acb9-c55ef7cc456e

STIX ID: report--7bf1d13e-332a-5b4a-acb9-c55ef7cc456e

Feed Name: Microsoft Security

Date Published: 2024-01-17

Date Updated: 2026-04-28

Author: Microsoft Incident Response

...
...

Microsoft Incident Response announces two concise guides to streamline investigations in Microsoft 365 and Microsoft Entra, focusing on high-value Unified Audit Log and Entra audit/sign-in events, access methods (portal, Graph PowerShell, Microsoft Graph API), and contextual cues for notable operations (e.g., SearchQuery*, SearchExportDownloaded, bulk actions, certificates/secrets updates, Elevate Access). The guidance emphasizes efficient data triage, correlation across logs, and recognizing behaviors commonly leveraged by threat actors to accelerate incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.