October 23, 2024 – Content Update

We are committed to continuously strengthening security operations for our customers through our innovative DARC Vault weekly releases. Just like Microsoft’s Patch Tuesday, the DARC Vault serves as a reliable source for enhanced security content, enabling our users to stay ahead of evolving threats.

Each week, we deliver the latest Out-Of-The-Box (OOTB) content that not only introduces brand-new capabilities but also enhances existing detections. This week, we are excited to announce a significant update focused on Microsoft 365. Our enhancements are designed to provide our users with advanced functionalities that improve performance and security monitoring across their environments.

This week’s content release emphasizes comprehensive security visibility and proactive threat detection across Microsoft 365 services. Below is a summary of the new additions and improvements:

Summary of Weekly Improvements

Content-TypeActionsCount
DetectionsNew32
 Enhanced37
DashboardsNew2
ReportsNew2

New Detections

#NameDescription
1Exchange Malware Filter Policy DeletionMonitors and alerts on the deletion of malware filter policies within Exchange.
2Microsoft 365 Exchange Malware Filter Rule ModificationTracks modifications to malware filter rules.
3Exchange Safe Attachment Rule DisabledAlerts on disabled safe attachment rules.
4Exchange Management Group Role AssignmentMonitors role assignments within Exchange management groups.
5Email Sent Success – External Users OnlyTracks successful emails sent to external users.
6External Domain Inbox Rule AlterationMonitors alterations to inbox rules affecting external domains.
7Exchange DLP Policy RemovedAlerts on the removal of data loss prevention (DLP) policies.
8MS-O365 Email Threat ActivityMonitors email activities related to identified threats.
9Microsoft 365 Exchange Anti-Phish Rule ModificationTracks modifications to anti-phishing rules.
10Exchange Transport Rule CreationAlerts on the creation of transport rules.
11Potential Password Spraying of Microsoft 365 AccountsMonitors for potential password spraying attempts.
12Exchange Transport Rule ModificationTracks modifications to transport rules.
13Microsoft 365 Teams Custom Application Interaction AllowedMonitors interactions with custom applications in Teams.
14Exchange Anti-Phish Policy DeletionAlerts on the deletion of anti-phishing policies.
15SharePoint Malware File UploadMonitors for malware uploads to SharePoint.
16OneDrive Malware File UploadTracks malware uploads to OneDrive.
17Microsoft 365 Teams External Access EnabledAlerts on enabling external access in Teams.
18Unusual Volume of File DeletionMonitors for unusual patterns of file deletion.
19Mailbox Audit Logging BypassAlerts on bypasses of mailbox audit logging.
20Global Administrator Role AssignedMonitors assignments to global administrator roles.
21Potential ransomware activityAlerts on activity indicative of potential ransomware.
22Attempts to Brute Force a Microsoft 365 User AccountMonitors for brute force login attempts on user accounts.
23User Restricted from Sending EmailAlerts when a user is restricted from sending emails.
24URL Detonation DetectionMonitors for malicious URLs and detonation attempts.
25Mailbox Right DelegationTracks delegation of mailbox rights.
26Email Threat DetectedAlerts on detected email threats.
27O365 Excessive Single Sign-On Logon ErrorsMonitors excessive SSO logon errors.
28Microsoft 365 Teams Guest Access EnabledAlerts on enabling guest access in Teams.
29Microsoft 365 Exchange Safe Link Policy DisabledMonitors when safe link policies are disabled.
30Microsoft 365 Exchange DKIM Signing Configuration DisabledAlerts when DKIM signing is disabled.
31Malware Detected on HostMonitors for malware detections on hosts.
32New or Modified Federation DomainAlerts on changes to federation domains.

New Dashboards

NameDescriptionValue Proposition
Microsoft – Office365 – Account and Policy ManagementProvides insights into account and policy configurations within Microsoft 365.Facilitates visibility into user permissions and policy adherence.
Microsoft – Office365 – Monitoring InsightsAggregates monitoring insights across Microsoft 365 services.Enhances situational awareness for security teams.

New Reports

NameDescriptionValue Proposition
Microsoft – Office365 – Monitoring ReportComprehensive report on monitoring activities and alerts in Microsoft 365.Provides detailed insights for compliance and security audits.
Microsoft – Office365 – Security ReportSummary of security incidents and metrics in Microsoft 365.Enhances understanding of security posture over time.

Enhancements to Existing Content

This week, we also enhanced several existing OOTB detections to improve their effectiveness and responsiveness. Below is the list of updated/enhanced content:

Content-TypeName
DetectionsProtocol or Port Mismatch
DetectionsClients Connecting to Multiple DNS Servers
DetectionsMultiple Successful Logins from Different Countries
DetectionsPPTP Activity
DetectionsRDP from the Internet
DetectionsDetect Large Outbound ICMP Packets
DetectionsProtocol or Port Mismatch – Custom
DetectionsDetect Outbound SMB Traffic
DetectionsHigh DNS Requests From Same Source
DetectionsFTP Activity to the Internet
DetectionsFortiGate VPN SSL User Login Failed
DetectionsTelegram Bot API Request
DetectionsBrute Force Access
DetectionsSMTP to the Internet
DetectionsUser Connected to Large Number of Systems
DetectionsFailed Config Changes by Same User
DetectionsDNS NXDOMAIN Flood
DetectionsSSH from the Internet
DetectionsLogins to Same System from Multiple Sources
DetectionsMultiple Login Failures From A Disabled Account
DetectionsProxy Port Activity to the Internet
DetectionsIPSEC NAT Traversal Port Activity
DetectionsLogin Failure From Expired Account
DetectionsDatabase Remote Login Success
DetectionsHigh Denied Traffic Within Short Period
DetectionsCryptocurrency Mining Network Communication
DetectionsSuccessful Login from Compromised User
DetectionsDistributed DOS Attack
DetectionsConcurrent Logins from Multiple Sources
DetectionsSMTP on Port 26 TCP
DetectionsFile Uploaded With Public Access
DetectionsIRC Protocol Activity to the Internet
DetectionsSuccessful Login From a Compromised Host
DetectionsAdmin User Remote Logon Detected
DetectionsRPC from the Internet
DetectionsRDP to the Internet