Microsoft Graph security alerts
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Goal
Detect when a Microsoft security product sends an alert to the Microsoft Graph security API.
Strategy
Microsoft Graph is the gateway to data and intelligence in Microsoft 365. It provides a unified programmability model that you can use to access the tremendous amount of data in Microsoft 365, Windows, and Enterprise Mobility + Security. This detections identifies when an alert from a Microsoft security product is raised and queried through the Microsoft Graph security API.
What happened
{{@triggering_event.description}}
Triage and response
{{@triggering_event.recommendedActions}}
If the alert is benign, consider including the user, host, or IP address in a suppression list. See Best practices for creating detection rules with Datadog Cloud SIEM for more information.