Tag
M365 or Entra ID Identity Sign-in from a Suspicious Source
2 rules 1 TTPThis rule correlates Entra-ID or Microsoft 365 mail successful sign-in events with network security alerts by source address, indicating potential initial access via compromised credentials.
CVE-2026-42893: M365 Copilot Command Injection Vulnerability
1 rule 1 TTP 1 CVECVE-2026-42893 is a command injection vulnerability in M365 Copilot that allows an unauthorized attacker to perform tampering over a network.
M365 or Entra ID Identity Sign-in from a Suspicious Source
2 rules 1 TTPCorrelates successful Entra ID or Microsoft 365 sign-in events with network security alerts based on the source IP address, indicating potential initial access from suspicious sources.
M365 Copilot Application Usage Pattern Anomalies
2 rules 1 TTPThis detection identifies anomalous M365 Copilot usage patterns indicative of potential account compromise or automated abuse by flagging users accessing Copilot from multiple locations, generating excessive daily activity, or utilizing multiple Copilot applications.
M365 Copilot Access from Non-Compliant Devices
2 rules 1 TTPDetects Microsoft 365 (M365) Copilot access from non-compliant or unmanaged devices, potentially indicating shadow IT, BYOD policy violations, or compromised endpoints accessing sensitive data.
Detection of M365 Copilot Jailbreak Attempts via Prompt Injection
2 rules 1 TTPThis detection identifies attempts to jailbreak M365 Copilot by using prompt injection techniques to bypass safety controls and manipulate system behavior, potentially violating acceptable use policies.