**1. Why is internal fraud difficult to detect? **
- Access is by authorized users
- Taking out data in the middle of normal work
- Tools or services are misused (e.g., OneDrive sharing, Teams transfer)
In other words, in most cases, there is no "clear alert".
2. Key logs you can get in Microsoft 365
- Audit Log
Target systems: SharePoint / OneDrive / Exchange / Teams
Features: File manipulation, sharing, email sending, chat sending, etc. - Sign-in Log
Eligible systems: Entra ID (formerly Azure AD)
Features: Login success/failure, risk-based judgment - Defender for Cloud Apps
Target system: Various SaaS usage and anomaly detection
Feature: Transfer, upload, and external sharing detection
3. Beware of such behavior! Internal fraud sign patterns
- Taking out information
・Sharing a large number of files externally with OneDrive → Audit log (OneDrive sharing operation)
- Large number of zip files from SharePoint in a short period of time → Download event + access frequency - Impersonation and Unauthorized Use
・Login from overseas IP late at night or on holidays → Sign-in log (IP × time × countries)
・Access from devices and browsers that you don't usually use → Sign-in logs (client app information) - Unusual behavior
- Send files to external users in Teams → Audit logs (Teams file shares)
- Set bulk forwarding rules in Exchange → Audit logs (inbound rule settings) - Retirement risk
・Abnormal file DL and email sending are concentrated before the last visit to work → Audit log + user attribute linkage
4. Colorkrew Security provides consistent support for internal fraud signs from analysis to visualization and reporting
Colorkrew Security provides the following services for Microsoft 365 environments:
- Search and store audit logs
- Leverage Microsoft 365 logs to visualize signs of fraud
- Monitoring of high-risk users of prospective retirees
- Alert security monitoring (24H365D)
5. Summary: Internal fraud countermeasures start with "log utilization"
- Fraud starts with legitimate users
→ You have no choice but to check logins and file operations - Microsoft 365 has enough logs
→ Utilizing audit logs + sign-in logs is key - Colorkrew supports all operations
→ Log acquisition, analysis, and monitoring can be provided at once
"Where should I start?" "I don't have anyone to analyze," "I want materials that can explain to management."
If you have such a problem, **Colorkrew Security has you covered! **
Please feel free to contact us.