email-and-collaboration
M365 email and collaboration security telemetry for detection engineering — Exchange Online mail flow (transport rules, journaling, DLP), mailbox delegation and forwarding rules, OAuth app permissions on mailboxes, SharePoint/OneDrive external sharing, Teams guest access, Purview Unified Audit Log (UAL) event types, MailItemsAccessed semantics, and BEC/phishing detection patterns. Use when authoring detections targeting email-based attacks, business email compromise, data exfiltration via collaboration tools, or insider threat indicators.
Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.
Files
Every link opens the file at its source, pinned to the revision this page describes.