Skip to content

Commit 6ec3536

Browse files
committed
fix(o365): drop actionResult gate on detection-type gap rules
FileMalwareDetected (RecordType 6) and AlertAdded (RecordType 78) are system-generated detections that carry no ResultStatus in production. KryonX's v1.4.1 filter (merged #2661) therefore never resolves actionResult=success for them, which would silently dead the rules. The event's presence is the signal, so match on action alone. Verified against the real filter + production data shapes: all 9 O365 gap rules now fire (MailboxLogin RT2/Succeeded, Set-CASMailbox + Add-MailboxFolderPermission + Remove-DlpPolicy + Set-MailboxAuditBypass RT1/True, Disable/UpdateConditionalAccessPolicy RT8/Success, MailItemsAccessed RT50/Succeeded, FileMalwareDetected RT6 + AlertAdded RT78 no-ResultStatus).
1 parent 90cb078 commit 6ec3536

2 files changed

Lines changed: 2 additions & 2 deletions

File tree

‎rules/office365/o365_file_malware_detected.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ description: |
2121
3. Remove or quarantine the file
2222
4. Assess the uploader for compromise
2323
where: |
24-
equals("action", "FileMalwareDetected") && equals("actionResult", "success")
24+
equals("action", "FileMalwareDetected")
2525
groupBy:
2626
- lastEvent.log.Parameters
2727
- adversary.user

‎rules/office365/o365_security_alert_added.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ description: |
2121
3. Triage and remediate per the alert guidance
2222
4. Document the incident and containment
2323
where: |
24-
equals("action", "AlertAdded") && equals("actionResult", "success")
24+
equals("action", "AlertAdded")
2525
groupBy:
2626
- lastEvent.log.Parameters
2727
- adversary.user

0 commit comments

Comments
 (0)