Use-Case Activity Type (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content Compromised Credentials scheduled_task-trigger:success (app-activity) ↳microsoft-azure-cef-app-activity-updatedevice ↳microsoft-azure-cef-app-activity-updateuser ↳microsoft-azure-cef-app-activity-addmembertogroup ↳microsoft-azure-cef-app-activity-updategroup ↳microsoft-azure-cef-app-activity-adduser T1078 - Valid AccountsT1133 - External Remote Services 39 Rules24 Models Data Access scheduled_task-trigger:success (app-activity) ↳microsoft-azure-cef-app-activity-updatedevice ↳microsoft-azure-cef-app-activity-updateuser ↳microsoft-azure-cef-app-activity-addmembertogroup ↳microsoft-azure-cef-app-activity-updategroup ↳microsoft-azure-cef-app-activity-adduser T1078 - Valid Accounts 19 Rules11 Models Data Leak scheduled_task-trigger:success (app-activity) ↳microsoft-azure-cef-app-activity-updatedevice ↳microsoft-azure-cef-app-activity-updateuser ↳microsoft-azure-cef-app-activity-addmembertogroup ↳microsoft-azure-cef-app-activity-updategroup ↳microsoft-azure-cef-app-activity-adduser T1114 - Email CollectionT1114.003 - Email Collection: Email Forwarding Rule 3 Rules Privilege Abuse scheduled_task-trigger:success (app-activity) ↳microsoft-azure-cef-app-activity-updatedevice ↳microsoft-azure-cef-app-activity-updateuser ↳microsoft-azure-cef-app-activity-addmembertogroup ↳microsoft-azure-cef-app-activity-updategroup ↳microsoft-azure-cef-app-activity-adduser app-activity:fail (app-activity-failed) ↳microsoft-azure-cef-app-activity-updatedevice ↳microsoft-azure-cef-app-activity-updateuser ↳microsoft-azure-cef-app-activity-addmembertogroup ↳microsoft-azure-cef-app-activity-updategroup ↳microsoft-azure-cef-app-activity-adduser T1078 - Valid AccountsT1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate Permissions 6 Rules2 Models Privilege Escalation scheduled_task-trigger:success (app-activity) ↳microsoft-azure-cef-app-activity-updatedevice ↳microsoft-azure-cef-app-activity-updateuser ↳microsoft-azure-cef-app-activity-addmembertogroup ↳microsoft-azure-cef-app-activity-updategroup ↳microsoft-azure-cef-app-activity-adduser T1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate Permissions 3 Rules1 Models Privileged Activity scheduled_task-trigger:success (app-activity) ↳microsoft-azure-cef-app-activity-updatedevice ↳microsoft-azure-cef-app-activity-updateuser ↳microsoft-azure-cef-app-activity-addmembertogroup ↳microsoft-azure-cef-app-activity-updategroup ↳microsoft-azure-cef-app-activity-adduser app-activity:fail (app-activity-failed) ↳microsoft-azure-cef-app-activity-updatedevice ↳microsoft-azure-cef-app-activity-updateuser ↳microsoft-azure-cef-app-activity-addmembertogroup ↳microsoft-azure-cef-app-activity-updategroup ↳microsoft-azure-cef-app-activity-adduser T1078 - Valid Accounts 2 Rules1 Models