office-365-dashboard

Description

A collection of custom dashboards to give you a holistic view of your Microsoft 365 environment. These dashboards can help you answer the following questions and more:

  • What files are users sharing internally and externally and with who? Are there users uploading or downloading an unusually large amount of data?
  • Who invited or added a guest user? Were they invited through a shared file or added directly through Active Directory?
  • Where in the world are users logging in from? Are there suspicious user agents attempting to login?
  • Which users receive the most suspicious mail? Where is this mail coming from?
  • What users does Azure AD consider to be risky and why?

The download includes a couple of Elastic Kibana dashboard as well as runtime field code to improve the data that comes from OOTB Elastic modules. To show the data you need to run the Azure and Office 365 module or Elastic Agent integration.

What is Microsoft Office 365?

Microsoft 365 is the productivity cloud. The complete solution includes  office applications, intelligent cloud services and advanced security. Microsoft Office 365 environments usually containing a lot of important company information. Its very important to observe and protect the usage and the information there.

Source

Originally found at https://github.com/ironvine/elastic-m365

Can also downloaded from Github directly.

Tested versions 7.14, 7.15
ECS compliant Yes

You must log in to submit a review.

Related downloads

OpenSIEM Logstash Parsing

Logstash Parsing Configurations for Elastic SIEM parses many different sources into ECS

Azure billing data network

A vega visualization that shows the connection between resource group, resource type and the resource itself based on Elastic agent azure billing data integration.

Logstash Meraki Pipeline

Logstash Pipeline to load Meraki logs via Syslog into Elasticsearch

Sigma AWS Cloudtrail Detection rules

A collection of rules based on the Sigma rules for AWS based on the Filebeat AWS module and Elastic agent integration.

Sigma Sysmon detection rules

A collection of rules based on the Sigma detection rules for Windows Sysmon events based on Winlogbeat data.

Office display canvas example

Kibana canvas example showing an office screen with weather, news and stock information

These downloads could be also interesting for you

Vega Scatterplot Kibana visualization

A scatterplot visualization made with Vega Lite for Kibana

Elasticsearch Performance Troubleshooting Kit

Download the Elasticsearch Performance Troubleshooting Kit to efficiently diagnose and resolve slow query issues in your Elasticsearch environment.

Impossible travel transform job

Impossible travel detection by calculating the distance between two login locations in combination with the time between the two logins

Vega Clock UTC

This is a working clock visualization in UTC time.

Kibana Maps with Open Weather Map

This is the default basemap of Kibana incl. the Open Weather Map tile for temperature, wind and pressure