Exchange mailbox audit bypass
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection, Email
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685)
Severity
Low
Description
A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection.
Attacker's Goals
An attacker may abuse the audit bypass mechanism to conceal actions and evade detection.
Investigative actions
Follow further actions done by the account.
Verify that the configuration change was expected.
Was this helpful?
