Skip to content

Latest commit

 

History

History
37 lines (30 loc) · 1.17 KB

b6c01dc5-a74b-435d-a22a-96b4f9f3168e.md

File metadata and controls

37 lines (30 loc) · 1.17 KB

Mappings: Microsoft Graph Security API C2C - Dynamic Vendor/Product - Microsoft 365 Defender

Input Requirements

Input Value
Vendor MS Sec Graph API - Microsoft
Product MS Sec Graph API - Microsoft 365 Defender
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Microsoft
Product Graph Security API
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userStates.1.aadUserId
description description
device_hostname hostStates.1.fqdn
device_ip hostStates.1.privateIpAddress
device_uniqueId azureTenantId
normalizedSeverity severity This is a lookup field. More info to come in the catalog later...
threat_category category
threat_identifier vendorInformation.provider
threat_name title
threat_ruleType None The static text direct is populated in this schema field.
threat_signalName %s - %s
timestamp eventDateTime We expect the orginal record value of eventDateTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ
user_username userStates.1.accountName