詳細検索

You can do this with Microsoft 365 logs! Analysis techniques to detect signs of internal fraud!

Avatar
by 西田
2 min read

You can do this with Microsoft 365 logs! Analysis techniques to detect signs of internal fraud!
Translated from 日本語 • View original
西田
西田

Hello! This is Nishida from Colorkrew Security. It is often said that "internal fraud is more troublesome than external attack". This is because the actions of people with "legitimate authority" are abused. In this article, we will introduce the perspective and specific analysis points for using Microsoft 365 logs to detect "signs of internal fraud".

**1. Why is internal fraud difficult to detect? **

  • Access is by authorized users
  • Taking out data in the middle of normal work
  • Tools or services are misused (e.g., OneDrive sharing, Teams transfer)

In other words, in most cases, there is no "clear alert".

2. Key logs you can get in Microsoft 365

  1. Audit Log
    Target systems: SharePoint / OneDrive / Exchange / Teams
    Features: File manipulation, sharing, email sending, chat sending, etc.
  2. Sign-in Log
    Eligible systems: Entra ID (formerly Azure AD)
    Features: Login success/failure, risk-based judgment
  3. Defender for Cloud Apps
    Target system: Various SaaS usage and anomaly detection
    Feature: Transfer, upload, and external sharing detection

3. Beware of such behavior! Internal fraud sign patterns

  1. Taking out information
    ・Sharing a large number of files externally with OneDrive → Audit log (OneDrive sharing operation)
    - Large number of zip files from SharePoint in a short period of time → Download event + access frequency
  2. Impersonation and Unauthorized Use
    ・Login from overseas IP late at night or on holidays → Sign-in log (IP × time × countries)
    ・Access from devices and browsers that you don't usually use → Sign-in logs (client app information)
  3. Unusual behavior
    - Send files to external users in Teams → Audit logs (Teams file shares)
    - Set bulk forwarding rules in Exchange → Audit logs (inbound rule settings)
  4. Retirement risk
    ・Abnormal file DL and email sending are concentrated before the last visit to work → Audit log + user attribute linkage

4. Colorkrew Security provides consistent support for internal fraud signs from analysis to visualization and reporting

Colorkrew Security provides the following services for Microsoft 365 environments:

  • Search and store audit logs
  • Leverage Microsoft 365 logs to visualize signs of fraud
  • Monitoring of high-risk users of prospective retirees
  • Alert security monitoring (24H365D)

5. Summary: Internal fraud countermeasures start with "log utilization"

  • Fraud starts with legitimate users
    → You have no choice but to check logins and file operations
  • Microsoft 365 has enough logs
    → Utilizing audit logs + sign-in logs is key
  • Colorkrew supports all operations
    → Log acquisition, analysis, and monitoring can be provided at once

"Where should I start?" "I don't have anyone to analyze," "I want materials that can explain to management."
If you have such a problem, **Colorkrew Security has you covered! **
Please feel free to contact us.

Related Articles