Security & Compliance Center alert events

OperationDescriptionSampleRule
anyCatch-all for M365-SecurityComplianceAlerts rules matching the RecordType but no specific Operation.NY
AlertEntityGeneratedAn entity was added to a Microsoft 365 security/compliance alert generated by an alert policy in the Microsoft Defender / Purview portal.YY
AlertTriggeredA Security & Compliance Center alert policy was triggered by activity matching the policy conditions.YY
AlertUpdatedThe status or details of a Security and Compliance alert were updated (for example triage or resolution).YN

any: Security & Compliance Center alert events (catch-all)

#
RecordType
SecurityComplianceAlerts

Description

Catch-all for M365-SecurityComplianceAlerts rules matching the RecordType but no specific Operation.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.provider1 detection ruleElastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Purview Security Compliance Signal source low: Collects alerts generated by Microsoft Purview (formerly Office 365 Security & Compliance Center) through the SecurityComplianceCenter provider. These alerts represent policy violations, compliance issues, and threats detected by Microsoft Purview's built-in detection capabilities including DLP policy matches, eDiscovery actions, retention policy violations, and other compliance-related events. This building block rule generates security events for correlation, threat hunting, and telemetry collection without creating standalone alerts, reducing alert fatigue while maintaining comprehensive visibility into Microsoft Purview's compliance and security detections.

References #

AlertEntityGenerated

#
RecordType
SecurityComplianceAlerts

Description

An entity was added to a Microsoft 365 security/compliance alert generated by an alert policy in the Microsoft Defender / Purview portal.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Name4 detection rulesSplunk
Operation4 detection rulesSplunk
Workload3 detection rulesSplunk
RescanVerdict1 detection ruleSplunk

Example Audit Record #

{
  "CreationTime": "2024-03-25T21:56:29",
  "Id": "bac7174a-19a9-4374-55fb-08dc4d166d45",
  "Operation": "AlertEntityGenerated",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 40,
  "ResultStatus": "Succeeded",
  "UserKey": "SecurityComplianceAlerts",
  "UserType": 4,
  "Version": 1,
  "Workload": "SecurityComplianceCenter",
  "ObjectId": "user15@splunkresearch.com",
  "UserId": "SecurityComplianceAlerts",
  "AlertEntityId": "user15@splunkresearch.com",
  "AlertId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
  "AlertLinks": [
    {
      "AlertLinkHref": ""
    }
  ],
  "AlertType": "System",
  "Category": "ThreatManagement",
  "Comments": "New alert",
  "Data": {
    "etype": "User",
    "eid": "user15@splunkresearch.com",
    "tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
    "ts": "2024-03-25T21:54:22.0000000Z",
    "te": "2024-03-25T21:54:22.0000000Z",
    "op": "MailRedirect",
    "tdc": "1",
    "suid": "user15@splunkresearch.com",
    "ut": "Regular",
    "ssic": "0",
    "lon": "MailRedirect"
  },
  "EntityType": "User",
  "Name": "Creation of forwarding/redirect rule",
  "PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
  "Severity": "Informational",
  "Source": "Office 365 Security & Compliance",
  "Status": "Active"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
Name (splunk rule field)containsa potentially malicious url1 rulesplunk
Name (splunk rule field)containsmessages containing malicious1 rulesplunk
Name (splunk rule field)inemail sending limit exceeded1 rulesplunk
Name (splunk rule field)insuspicious email forwarding activity1 rulesplunk
Name (splunk rule field)insuspicious email sending patterns detected1 rulesplunk
Name (splunk rule field)inuser restricted from sending email1 rulesplunk
Name (splunk rule field)starts_withemail reported by user as1 rulesplunk
RescanVerdict (splunk rule field)inmalware1 rulesplunk
RescanVerdict (splunk rule field)inphish1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • O365 Email Reported By User Found Malicious source: The following analytic detects when an email submitted to Microsoft using the built-in report button in Outlook is found to be malicious. This capability is an enhanced protection feature that can be used within o365 tenants by users to…T1566, T1566.001, T1566.002
  • O365 Email Suspicious Behavior Alert source: The following analytic identifies when one of O365 the built-in security detections for suspicious email behaviors are triggered. These alerts often indicate that an attacker may have compromised a mailbox within the environment. Any…T1114, T1114.003
  • O365 Safe Links Detection source: The following analytic detects when any Microsoft Safe Links alerting is triggered. This behavior may indicate when user has interacted with a phishing or otherwise malicious link within the Microsoft Office ecosystem.T1566, T1566.001

References #

AlertTriggered

#
RecordType
SecurityComplianceAlerts

Description

A Security & Compliance Center alert policy was triggered by activity matching the policy conditions.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Category1 detection ruleSplunk
event.action1 detection ruleElastic
event.provider1 detection ruleElastic
Operation1 detection ruleSplunk
rule.name1 detection ruleElastic
Workload1 detection ruleSplunk

Example Audit Record #

{
  "CreationTime": "2024-03-25T21:56:29",
  "Id": "95428ddb-9aa0-4bcf-84f4-08dc4d166d4c",
  "Operation": "AlertTriggered",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 40,
  "ResultStatus": "Succeeded",
  "UserKey": "SecurityComplianceAlerts",
  "UserType": 4,
  "Version": 1,
  "Workload": "SecurityComplianceCenter",
  "ObjectId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
  "UserId": "SecurityComplianceAlerts",
  "AlertId": "95adeea5-ede1-136f-5200-08dc4d1637c4",
  "AlertLinks": [
    {
      "AlertLinkHref": ""
    }
  ],
  "AlertType": "System",
  "Category": "ThreatManagement",
  "Comments": "New alert",
  "Data": {
    "f3u": "user15@splunkresearch.com",
    "ts": "2024-03-25T21:54:00.0000000Z",
    "te": "2024-03-25T21:55:00.0000000Z",
    "op": "MailRedirect",
    "wl": "Exchange",
    "tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
    "tdc": "1",
    "reid": "136169be-3964-4b4c-2087-08dc4d1621a2",
    "wsrt": "2024-03-25T21:56:18",
    "mdt": "Audit",
    "rid": "0c04b79b-9148-4950-af22-2657dd53a92c",
    "cid": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
    "ad": "This alert is triggered when someone in your organization sets up auto-forwarding, email forwarding, redirect rule or a mail flow rule -V1.0.0.5",
    "lon": "MailRedirect",
    "an": "Creation of forwarding/redirect rule",
    "sev": "Informational"
  },
  "Name": "Creation of forwarding/redirect rule",
  "PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
  "Severity": "Informational",
  "Source": "Office 365 Security & Compliance",
  "Status": "Active"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
Category (splunk rule field)eqthreatmanagement1 rulesplunk
rule.name (elastic rule field)eqemail reported by user as malware or phish1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

References #

AlertUpdated

#
RecordType
SecurityComplianceAlerts

Description

The status or details of a Security and Compliance alert were updated (for example triage or resolution).

Example Audit Record #

{
  "CreationTime": "2024-03-25T21:54:15",
  "Id": "0d0eee3a-7bbe-005f-54eb-08dc4d161d48",
  "Operation": "AlertUpdated",
  "OrganizationId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
  "RecordType": 40,
  "ResultStatus": "Succeeded",
  "UserKey": "SecurityComplianceAlerts",
  "UserType": 4,
  "Version": 1,
  "Workload": "SecurityComplianceCenter",
  "ObjectId": "95adeea5-ede1-136f-ae00-08dc4d156130",
  "UserId": "SecurityComplianceAlerts",
  "AlertId": "95adeea5-ede1-136f-ae00-08dc4d156130",
  "AlertLinks": [
    {
      "AlertLinkHref": ""
    }
  ],
  "AlertType": "System",
  "Category": "ThreatManagement",
  "Comments": "New alert",
  "Data": {
    "f3u": "user15@splunkresearch.com",
    "ts": "2024-03-25T21:48:00.0000000Z",
    "te": "2024-03-25T21:49:00.0000000Z",
    "op": "MailRedirect",
    "wl": "Exchange",
    "tid": "75243ab2-44f8-435c-a7a6-b479385df6d4",
    "tdc": "1",
    "reid": "884b4cf9-3329-47aa-7241-08dc4d1556b2",
    "wsrt": "2024-03-25T21:53:15",
    "mdt": "Audit",
    "rid": "0c04b79b-9148-4950-af22-2657dd53a92c",
    "cid": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
    "ad": "This alert is triggered when someone in your organization sets up auto-forwarding, email forwarding, redirect rule or a mail flow rule -V1.0.0.5",
    "lon": "MailRedirect",
    "an": "Creation of forwarding/redirect rule",
    "sev": "Informational"
  },
  "Name": "Creation of forwarding/redirect rule",
  "PolicyId": "d59a8fd4-1272-41ee-9408-86f7bcf72479",
  "Severity": "Informational",
  "Source": "Office 365 Security & Compliance",
  "Status": "Active"
}

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.