|
259 | 259 | "user": {
|
260 | 260 | "id": "SecurityComplianceAlerts"
|
261 | 261 | }
|
| 262 | + }, |
| 263 | + { |
| 264 | + "@timestamp": "2025-06-03T08:10:44.000Z", |
| 265 | + "ecs": { |
| 266 | + "version": "8.11.0" |
| 267 | + }, |
| 268 | + "email": { |
| 269 | + "local_id": [ |
| 270 | + "aaaa109-bbb-cccc-dddd-eeeea1c1dd41" |
| 271 | + ], |
| 272 | + "message_id": [ |
| 273 | + "[email protected](external, opens in a new tab or window)" |
| 274 | + ], |
| 275 | + "sender": { |
| 276 | + "address": [ |
| 277 | + "[email protected](external, opens in a new tab or window)" |
| 278 | + ] |
| 279 | + }, |
| 280 | + "subject": [ |
| 281 | + "Welkom op My company" |
| 282 | + ], |
| 283 | + "to": { |
| 284 | + "address": [ |
| 285 | + "[email protected](external, opens in a new tab or window)" |
| 286 | + ] |
| 287 | + } |
| 288 | + }, |
| 289 | + "event": { |
| 290 | + "action": "AlertEntityGenerated", |
| 291 | + "category": [ |
| 292 | + "web" |
| 293 | + ], |
| 294 | + "code": "SecurityComplianceAlerts", |
| 295 | + "id": "aaaabce60-bbbb-cccc-dddd-eeeea27623da", |
| 296 | + "kind": "alert", |
| 297 | + "original": "{\"Category\":\"ThreatManagement\",\"UserKey\":\"SecurityComplianceAlerts\",\"Operation\":\"AlertEntityGenerated\",\"OrganizationId\":\"aaaaa14f-bbbb-cccc-dddd-eeee5a778630\",\"AlertEntityId\":\" [email protected](external, opens in a new tab or window)\",\"Source\":\"Office 365 Security & Compliance\",\"Name\":\"Email reported by user as malware or phish\",\"AlertType\":\"System\",\"RecordType\":40,\"Version\":1,\"Status\":\"Active\",\"ObjectId\":\" [email protected](external, opens in a new tab or window)\",\"ResultStatus\":\"Succeeded\",\"Comments\":\"New alert\",\"AlertLinks\":[{\"AlertLinkHref\":\"\"}],\"Data\":\"{\\\"etype\\\":\\\"User\\\",\\\"eid\\\":\\\" [email protected](external, opens in a new tab or window)\\\",\\\"tid\\\":\\\"aaaaa14f-bbbb-cccc-dddd-eeee5a778630\\\",\\\"ts\\\":\\\"2025-05-02T05:10:44.5371861Z\\\",\\\"te\\\":\\\"2025-05-02T05:10:44.5371861Z\\\",\\\"op\\\":\\\"UserSubmission\\\",\\\"tdc\\\":\\\"1\\\",\\\"suid\\\":\\\" [email protected](external, opens in a new tab or window)\\\",\\\"ut\\\":\\\"Regular\\\",\\\"ssic\\\":\\\"0\\\",\\\"tsd\\\":\\\" [email protected](external, opens in a new tab or window)\\\",\\\"sip\\\":\\\"\\\",\\\"imsgid\\\":\\\" [email protected](external, opens in a new tab or window)\\\",\\\"srt\\\":\\\"1\\\",\\\"trc\\\":\\\" [email protected](external, opens in a new tab or window)\\\",\\\"ms\\\":\\\"Welkom op My company\\\",\\\"sid\\\":\\\"aaa174f-bbbb-cccc-dddd-eeeea27623b4\\\",\\\"aii\\\":\\\"aaaa109-bbb-cccc-dddd-eeeea1c1dd41\\\",\\\"md\\\":\\\"2025-05-02T10:40:16.9298292Z\\\",\\\"etps\\\":\\\"SubmissionId:aaaae50f-bbbb-4760-cccc-dddda276218e\\\",\\\"lon\\\":\\\"UserSubmission\\\"}\",\"Severity\":\"Low\",\"Workload\":\"SecurityComplianceCenter\",\"EntityType\":\"User\",\"AlertId\":\"aaaa01b-bbbb-cccc-dddd-eeeea276218e\",\"UserId\":\"SecurityComplianceAlerts\",\"CreationTime\":\"2025-06-03T08:10:44\",\"Id\":\"aaaabce60-bbbb-cccc-dddd-eeeea27623da\",\"UserType\":4,\"PolicyId\":\"aaaa5770-bbbb-cccc-dddd-eeee2c27bbb3\"}", |
| 298 | + "outcome": "success", |
| 299 | + "provider": "SecurityComplianceCenter", |
| 300 | + "type": [ |
| 301 | + "info" |
| 302 | + ] |
| 303 | + }, |
| 304 | + "host": { |
| 305 | + "id": "aaaaa14f-bbbb-cccc-dddd-eeee5a778630" |
| 306 | + }, |
| 307 | + "message": "Email reported by user as malware or phish", |
| 308 | + "o365": { |
| 309 | + "audit": { |
| 310 | + "AlertId": "aaaa01b-bbbb-cccc-dddd-eeeea276218e", |
| 311 | + "AlertType": "System", |
| 312 | + "Comments": "New alert", |
| 313 | + "CreationTime": "2025-06-03T08:10:44", |
| 314 | + "Data": { |
| 315 | + "aii": "aaaa109-bbb-cccc-dddd-eeeea1c1dd41", |
| 316 | + "eid": "[email protected](external, opens in a new tab or window)", |
| 317 | + "etps": "SubmissionId:aaaae50f-bbbb-4760-cccc-dddda276218e", |
| 318 | + "etype": "User", |
| 319 | + "flattened": { |
| 320 | + "aii": "aaaa109-bbb-cccc-dddd-eeeea1c1dd41", |
| 321 | + "eid": "[email protected](external, opens in a new tab or window)", |
| 322 | + "etps": "SubmissionId:aaaae50f-bbbb-4760-cccc-dddda276218e", |
| 323 | + "etype": "User", |
| 324 | + "imsgid": "[email protected](external, opens in a new tab or window)", |
| 325 | + "lon": "UserSubmission", |
| 326 | + "md": "2025-05-02T10:40:16.9298292Z", |
| 327 | + "ms": "Welkom op My company", |
| 328 | + "op": "UserSubmission", |
| 329 | + "sid": "aaa174f-bbbb-cccc-dddd-eeeea27623b4", |
| 330 | + "srt": "1", |
| 331 | + "ssic": "0", |
| 332 | + "suid": "[email protected](external, opens in a new tab or window)", |
| 333 | + "tdc": "1", |
| 334 | + "te": "2025-05-02T05:10:44.5371861Z", |
| 335 | + "tid": "aaaaa14f-bbbb-cccc-dddd-eeee5a778630", |
| 336 | + "trc": "[email protected](external, opens in a new tab or window)", |
| 337 | + "ts": "2025-05-02T05:10:44.5371861Z", |
| 338 | + "tsd": "[email protected](external, opens in a new tab or window)", |
| 339 | + "ut": "Regular" |
| 340 | + }, |
| 341 | + "imsgid": "[email protected](external, opens in a new tab or window)", |
| 342 | + "lon": "UserSubmission", |
| 343 | + "md": "2025-05-02T10:40:16.929Z", |
| 344 | + "ms": "Welkom op My company", |
| 345 | + "op": "UserSubmission", |
| 346 | + "sid": "aaa174f-bbbb-cccc-dddd-eeeea27623b4", |
| 347 | + "srt": "1", |
| 348 | + "ssic": "0", |
| 349 | + "suid": "[email protected](external, opens in a new tab or window)", |
| 350 | + "tdc": "1", |
| 351 | + "te": "2025-05-02T05:10:44.537Z", |
| 352 | + "tid": "aaaaa14f-bbbb-cccc-dddd-eeee5a778630", |
| 353 | + "trc": "[email protected](external, opens in a new tab or window)", |
| 354 | + "ts": "2025-05-02T05:10:44.537Z", |
| 355 | + "tsd": "[email protected](external, opens in a new tab or window)", |
| 356 | + "ut": "Regular" |
| 357 | + }, |
| 358 | + "ObjectId": "[email protected](external, opens in a new tab or window)", |
| 359 | + "RecordType": "40", |
| 360 | + "ResultStatus": "Succeeded", |
| 361 | + "Severity": "Low", |
| 362 | + "Source": "Office 365 Security & Compliance", |
| 363 | + "Status": "Active", |
| 364 | + "UserId": "SecurityComplianceAlerts", |
| 365 | + "UserKey": "SecurityComplianceAlerts", |
| 366 | + "UserType": "4", |
| 367 | + "Version": "1" |
| 368 | + } |
| 369 | + }, |
| 370 | + "organization": { |
| 371 | + "id": "aaaaa14f-bbbb-cccc-dddd-eeee5a778630" |
| 372 | + }, |
| 373 | + "related": { |
| 374 | + "user": [ |
| 375 | + "[email protected](external, opens in a new tab or window)", |
| 376 | + "[email protected](external, opens in a new tab or window)" |
| 377 | + ] |
| 378 | + }, |
| 379 | + "rule": { |
| 380 | + "category": "ThreatManagement", |
| 381 | + "description": "[email protected](external, opens in a new tab or window)", |
| 382 | + "id": "aaaa5770-bbbb-cccc-dddd-eeee2c27bbb3", |
| 383 | + "name": "Email reported by user as malware or phish", |
| 384 | + "ruleset": "User" |
| 385 | + }, |
| 386 | + "tags": [ |
| 387 | + "preserve_original_event" |
| 388 | + ], |
| 389 | + "user": { |
| 390 | + "id": "SecurityComplianceAlerts" |
| 391 | + } |
262 | 392 | }
|
263 | 393 | ]
|
264 | 394 | }
|
0 commit comments