Detection reference
Corelog runs 13 heuristics against the loaded audit log. Each is mapped to a MITRE ATT&CK technique, and every threshold, window and baseline is stated below — if a tool flags an event you should be able to explain exactly why to whoever asks. Detections that depend on location resolve the country from the client IP against a database bundled with the app, because Purview’s own GeoLocation field carries a datacenter region rather than a country on most tenants.
Impossible Travel
Section titled “Impossible Travel”MITRE: T1078 — Valid Accounts · Severity: High
Fires when two consecutive SIGN-IN events for the same user originate from countries whose geographic centroids are more than 1,000 km apart and are separated by less than 1 hour. The distance is calculated using the Haversine formula against ISO-3166-1 alpha-2 country codes. A single flag is raised on both the earlier and later event. Only interactive authentication counts as evidence of where a person was — UserLoggedIn, UserLoginFailed, SignInEvent, PasswordLogonInitialAuthUsingPassword, TeamsSessionStarted and EmailAuthOTPAuthenticationSucceeded. File and mail operations are excluded because their IP is routinely Microsoft infrastructure acting on the user behalf (background sync, indexing, mobile push), which would otherwise make every mailbox appear to teleport between datacenters. The country is resolved from the client IP against an offline database; Purview GeoLocation field is only used when it genuinely contains a country code, since for SharePoint it carries the multi-geo datacenter region instead. Indicates a credential being used from two physically incompatible locations — typically stolen credentials or a VPN/proxy masking the true origin.
Off-Hours Access
Section titled “Off-Hours Access”MITRE: T1078.004 — Cloud Accounts · Severity: Medium
Fires on every event whose creation timestamp falls in the window 22:00–06:00 in the time zone selected for the investigation, with daylight saving applied on the correct dates. The zone is shown in the toolbar and named on every finding, because the same export analysed in another zone produces different answers. No user baseline is required; the window is fixed rather than learned, and one zone is applied to the whole export — an organisation spread across several will see a normal morning in one office counted as off-hours. Read it alongside Unusual Day for User, which does learn each user’s rhythm. Unusually high off-hours activity — especially involving data access or deletion operations — is a common indicator of an attacker operating from a different timezone or an insider threat acting outside monitored hours.
Bulk Operations
Section titled “Bulk Operations”MITRE: T1567 / T1485 — Exfiltration Over Web / Data Destruction · Severity: High / Critical
Fires when the same account performs the same operation ≥20 times within a 60-second sliding window. If the operation belongs to the Deletion category the flag maps to T1485 (Data Destruction, Critical); otherwise it maps to T1567 (Exfiltration Over Web Service, High).
Two things this detector deliberately does. Operations classified as automatic are not counted. A mail client synchronising a folder reads twenty items a second all day, and on a 132,867-event export 942 of the 991 bursts present were exactly that — reported as exfiltration at high severity, they buried the 49 a person actually caused. Which operations are set aside is under your control; see Interactive and automatic activity. Every burst is reported, not only the first per account and operation. The same export reported 12 bursts where 991 existed, because a deletion spree in January hid one in June.
Typical genuine triggers: mass file downloads, bulk deletion of mailbox items, or a script creating many sharing links.
Unmanaged Device
Section titled “Unmanaged Device”MITRE: T1078 — Valid Accounts · Severity: Medium
Fires when an event with isManagedDevice === false involves a sensitive operation. Sensitive operations are: FileDownloaded, FileSyncDownloadedFull, FileSyncUploadedFull, FileRecycled, FileDeleted, AnonymousLinkCreated, SharingInvitationCreated, CompanyLinkCreated, SharingSet — or any event in the Deletion, Sharing, or Modification category. Unmanaged devices bypass Conditional Access policies and MDM controls, making them a common pivot point for both external attackers and malicious insiders.
New Geography
Section titled “New Geography”MITRE: T1078 — Valid Accounts · Severity: Medium
Fires on the first SIGN-IN where a user is seen from a country not previously observed for that user in the dataset. Events are processed in chronological order; the first event from each country establishes the baseline, so only subsequent first-appearances raise a flag. It uses the same evidence rule as Impossible Travel — only interactive authentication events count, because background service access originating in a Microsoft datacenter is not the user appearing in a new country. The country is resolved from the client IP against an offline database. A single new-geography event is low signal on its own; combined with off-hours or bulk-operations flags it is a strong indicator of account compromise.
First-Time Application
Section titled “First-Time Application”MITRE: T1550 — Use Alternate Authentication Material · Severity: Low
Fires the first time a user generates events attributed to an application (appDisplayName or clientAppName) not previously seen for that user in the dataset. Events are processed chronologically. The flag is not raised for the very first application a user uses — only for subsequent new ones. Attacker tooling (e.g. AADInternals, ROADtools) often authenticates as uncommon or undocumented application IDs, making this a useful low-noise signal when combined with other anomalies.
New Device
Section titled “New Device”MITRE: T1078 — Valid Accounts · Severity: Medium
Fires the first time a user generates events from a device identifier (machineId or deviceName) not previously observed for that user in the dataset. Events are processed chronologically. The device is only considered ‘new’ if the user has at least one prior event on a different known device. A new device appearing alongside off-hours or impossible-travel flags strongly suggests account compromise or an attacker operating with cloned credentials on a fresh machine.
External Sharing Burst
Section titled “External Sharing Burst”MITRE: T1567.002 — Exfiltration to Cloud Storage · Severity: High
Fires when an account creates or modifies ≥5 sharing links or invitations within a 10-minute sliding window, grouped per account. It tracks all 16 operations that grant access to a file or a link — the SharingSet, SharingLink, SecureLink, CompanyLink, AnonymousLink and SharingInvitation families. That is the same set the audit report’s sharing check examines, so the two cannot disagree about what counts as sharing; an earlier version tracked five of them and left 173 of 303 sharing events in one export unexamined. This pattern is characteristic of pre-exfiltration staging, where an attacker bulk-creates anonymous or guest sharing links to move data out of the tenant without triggering DLP policies designed for direct downloads.
Mailbox Forwarding Rule
Section titled “Mailbox Forwarding Rule”MITRE: T1114.003 — Email Forwarding Rule · Severity: Critical
Fires when a New-InboxRule or Set-InboxRule operation is found and the raw AuditData JSON contains any of the following keywords (case-insensitive): forwardto, forwardasattachmentto, redirectto, forwardsmssto. This heuristic detects the creation or modification of inbox rules that silently copy or redirect incoming mail to an external address — a textbook Business Email Compromise (BEC) persistence technique that survives password resets.
Audit Log Tamper
Section titled “Audit Log Tamper”MITRE: T1562.008 — Disable or Modify Cloud Logs · Severity: Critical / Medium
Fires when Set-AdminAuditLogConfig, Set-MailboxAuditBypassAssociation or Set-OrganizationConfig is executed. The severity depends on what the record shows, and the two cases read differently:
- Critical — the record shows an audit switch being moved to the value that weakens the log: UnifiedAuditLogIngestionEnabled, AdminAuditLogEnabled, MailboxAuditEnabled or AuditEnabled set to false, or AuditBypassEnabled set to true. The direction matters:
AuditBypassEnabled = Falseis somebody switching logging back on, and is not tampering. - Medium — the operation ran but the record does not carry what it changed. The finding says exactly that rather than assuming the worst, because a routine configuration change looks identical from the outside.
Evidence is read from ModifiedProperties first and from the raw AuditData second. The raw column is discarded for large exports, which is where real tenant activity lives, so a check that only read it would work on a sample and quietly stop working on a real file.
Disabling audit logging is a defence-evasion technique used to suppress evidence of subsequent actions.
Authentication Anomaly Cluster
Section titled “Authentication Anomaly Cluster”MITRE: T1110 — Brute Force · Severity: High
Fires when ≥10 distinct source addresses produce failed sign-ins within a 5-minute sliding window. The window is not account-scoped: it looks at the whole export, and the finding names how many accounts were involved. A high count of distinct addresses failing to authenticate in a short window is the canonical signature of a password spray, where the adversary rotates source addresses to evade per-address rate limiting.
Successful sign-ins do not count. Ten people signing in normally from ten offices in the same five minutes is a Monday morning, not an attack. Every cluster is reported, not only the first in the file.
This shape needs many addresses, so it cannot fire on an export covering a single account — which is the ordinary case for this tool. The detection below covers the shape that can.
Repeated Sign-in Failures
Section titled “Repeated Sign-in Failures”MITRE: T1110 — Brute Force · Severity: Medium
Fires when one account records ≥5 failed sign-ins from one address within a 10-minute sliding window. One flag per burst, raised on its first event, so a single episode appears once rather than five times.
Keyed on the operation name (UserLoginFailed) rather than on ResultStatus, which is absent from roughly a sixth of events — on one reference export 14 events were UserLoginFailed and only 7 carried a result status at all.
Severity is medium on purpose. Somebody retyping a forgotten password after their train changed networks produces exactly this shape, and so does a colleague on hotel wifi. The value of the finding is that it is visible and can be dismissed with a reason, not that it is damning.
Unusual Day for User
Section titled “Unusual Day for User”MITRE: T1078 — Valid Accounts · Severity: Medium / High
Fires when a user’s activity on a given day is far above what that user normally does on that day of the week. The weekly rhythm is learned from the loaded file, per user — nothing assumes when people work, so a tenant running 24/7, Sunday–Thursday, or busiest at weekends is handled identically, and a quiet Thursday in a weekend-heavy business is just as flaggable as a busy Sunday in an office one. Daily counts are compared in log space against the median of that user’s other same-weekday values; the day being tested is always excluded from its own baseline, so a large anomaly cannot inflate the expectation it is measured against. The cut is a robust-statistics constant — Iglewicz-Hoaglin modified z ≥ 3.5, computed against the spread of the loaded dataset itself — rather than a fixed multiplier, which would only ever be right for the organisation it was tuned on. Only upward deviations are reported: a quiet day is not evidence of compromise. A minimum of three observations per weekday per user is required (roughly three weeks of history); with less, the detector reports insufficient history instead of guessing. One flag is raised per anomalous day, not per event, so a single unusual day does not bury the report under its own volume.