kurtsh<p>Do you need a "one page" guide to investigate suspicious activity in Microsoft 365 and Microsoft Entra?</p><p>This guide contains the artifacts that Microsoft Incident Response hunts for and uses daily. This includes E-mail manipulations, Data collections, Login events etc. </p><p>You can also read & download more here: <a href="https://www.microsoft.com/en-us/security/blog/2024/01/17/new-microsoft-incident-response-guides-help-security-teams-analyze-suspicious-activity/?msockid=0f62e881cee7693e2d81fc18cf1268e1" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">microsoft.com/en-us/security/b</span><span class="invisible">log/2024/01/17/new-microsoft-incident-response-guides-help-security-teams-analyze-suspicious-activity/?msockid=0f62e881cee7693e2d81fc18cf1268e1</span></a></p><p><a href="https://mastodon.social/tags/microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>microsoft</span></a> <a href="https://mastodon.social/tags/irt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>irt</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/microsof365" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>microsof365</span></a> <a href="https://mastodon.social/tags/msftadvocate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>msftadvocate</span></a> <a href="https://mastodon.social/tags/entra" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>entra</span></a> <a href="https://mastodon.social/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>