cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Hashes of the attachment from the o365 log

L2 Linker

Dear community,


I've been evaluating the benefits of ingesting o365 logs so far. Seeking those who have the mentioned logs ingested into Cortex XDR -

does Cortex XDR review and raise alert using the hashes of the attachment if the attachment is a malware?

Besides, what are the useful data / alert that you think it helped your organization in terms of day-to-day operation/investigation?

 

Thank you
Cortex XDR 

AC
Who Me Too'd this topic