Infosec.Pub
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
digicatM to blueteamsecEnglish · 4 months ago

GraphApiAuditEvents: The new Graph API Logs

kqlquery.com

external-link
message-square
0
link
fedilink
3
external-link

GraphApiAuditEvents: The new Graph API Logs

kqlquery.com

digicatM to blueteamsecEnglish · 4 months ago
message-square
0
link
fedilink
This blog introduces the new GraphApiAuditEvents table in Microsoft Defender XDR’s Advanced Hunting, a cost-free alternative to the MicrosoftGraphActivityLogs previously available in Sentinel. It compares their schemas, ingestion rates, delays, retention policies, and cost implications, highlighting key differences such as missing fields and consolidated identifiers. The post also explores practical hunting techniques, including parsing and analyzing RequestUri for endpoint insights, generating resource statistics, and detecting tools like AzureHound. Finally, it offers guidance on when and how to transition from MicrosoftGraphActivityLogs to GraphApiAuditEvents to balance visibility, cost, and detection capability.
alert-triangle
You must log in or # to comment.

blueteamsec

blueteamsec

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !blueteamsec@infosec.pub

For [Blue|Purple] Teams in Cyber Defence - covering discovery, detection, response, threat intelligence, malware, offensive tradecraft and tooling, deception, reverse engineering etc.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 23 users / day
  • 98 users / week
  • 264 users / month
  • 860 users / 6 months
  • 218 local subscribers
  • 578 subscribers
  • 1.77K Posts
  • 144 Comments
  • Modlog
  • mods:
  • digicat
  • BE: 0.19.13
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org