Commit 6ec3536
committed
fix(o365): drop actionResult gate on detection-type gap rules
FileMalwareDetected (RecordType 6) and AlertAdded (RecordType 78) are
system-generated detections that carry no ResultStatus in production.
KryonX's v1.4.1 filter (merged #2661) therefore never resolves
actionResult=success for them, which would silently dead the rules.
The event's presence is the signal, so match on action alone.
Verified against the real filter + production data shapes: all 9 O365
gap rules now fire (MailboxLogin RT2/Succeeded, Set-CASMailbox +
Add-MailboxFolderPermission + Remove-DlpPolicy + Set-MailboxAuditBypass
RT1/True, Disable/UpdateConditionalAccessPolicy RT8/Success,
MailItemsAccessed RT50/Succeeded, FileMalwareDetected RT6 + AlertAdded
RT78 no-ResultStatus).1 parent 90cb078 commit 6ec3536
2 files changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
0 commit comments