Skip to main content
RAIDEN runs a large library of purpose-built detections against your Microsoft 365 activity continuously. Each detection targets a specific attack technique or abuse pattern seen in real M365 environments. This page describes what RAIDEN covers, grouped by attack category, and how findings turn into investigations. RAIDEN ships 269 detection rules in total — 145 detections (each can open or escalate a Case) and 124 signals (enrichment evidence that strengthens an existing Case). You don’t manage these individually; RAIDEN evaluates all of them automatically and only surfaces what matters as a Case.

How detections work

RAIDEN ingests Microsoft 365 activity on a continuous poll cycle and evaluates it against the full detection library. Identity sign-in activity is polled on a fast cadence — roughly every 2 minutes — so account-takeover signals surface quickly. Other workloads (mailbox, SharePoint, Teams, Defender alerts) are polled on their own cadences. When a detection’s conditions are met, a finding is created. Related findings for the same user are grouped into a Case with an AI-generated investigation report that lays out what happened, the supporting evidence, and a recommended verdict. Lower-weight signals attach to that Case as corroborating evidence rather than opening Cases of their own. Detections are:
  • Per-user scoped — findings are attributed to a specific user account, so a Case reads as a coherent story about one identity.
  • Evidence-layered — a Case combines high-confidence detections with supporting signals across multiple Microsoft data sources rather than relying on any single indicator.
  • Tunable via suppression — if a detection fires on known-safe activity, you can suppress it per IP, application, or user. See Cases & Alerts — Suppression.

Identity, sessions & AiTM

The largest part of RAIDEN’s coverage. RAIDEN reconstructs each user’s authentication sessions from Entra ID sign-in activity and looks for the hallmarks of account takeover and adversary-in-the-middle (AiTM) phishing. What this covers:
  • AiTM phishing — sign-in patterns and infrastructure consistent with token-stealing reverse proxies, including fingerprint matches against known phishing-as-a-service kits (FlowerStorm, Tycoon 2FA, EvilProxy, Mamba 2FA and variants).
  • Token theft & session hijacking — the same session reused from a different origin, replayed or unbound tokens, and tokens minted from suspicious infrastructure.
  • Impossible travel & geo anomalies — successful sign-ins from locations too far apart to be physically possible in the elapsed time, and sudden geographic spread within one session.
  • Suspicious sign-in infrastructure — sign-ins from networks associated with attacker hosting, anonymising proxies, consumer VPNs, and residential-proxy services, scored by reputation tier rather than treated as an automatic verdict.
  • Behavioural baseline deviations — once RAIDEN has learned a user’s normal pattern, it flags first-time countries, unusual sign-in hours, new device or user-agent families, and login-frequency spikes.
These run together so a single compromised session is assembled from many corroborating pieces of evidence rather than one noisy alert.

Phishing & token-grab techniques

Detections for the specific ways attackers trick a user into handing over access:
  • Device-code phishing — abuse of the OAuth device-code flow to capture a refresh token without ever needing the victim’s password, including detection of completed device-code token theft and device-code use that deviates from the user’s baseline.
  • Phishing-kit infrastructure matches — sign-ins from IPs and infrastructure tied to known AiTM kits and credential-stuffing campaigns, matched against a continuously maintained threat-intel set.
  • Malicious URL clicks — confirmed and suspicious malicious-link clicks surfaced from Microsoft Defender for Office 365.
  • Forms-based phishing — Microsoft Forms used as a credential-harvesting lure.

Attackers increasingly persist through OAuth apps rather than stolen passwords. RAIDEN watches the consent and app-registration surface:
  • Suspicious consent grants — OAuth consent to apps requesting high-privilege scopes, apps with suspicious names, or consent that immediately follows a risky sign-in.
  • Known-abused applications — consent to apps already associated with abuse.
  • App-registration & credential abuse — new app registrations, injection of credentials onto an existing app, federated-credential additions, silent scope expansion, app-role escalation, and localhost-redirect patterns consistent with C2 callbacks.
  • Fast identity-to-OAuth pivots — a compromised identity granting an OAuth app moments after takeover.

MFA, password & credential attacks

  • MFA tampering & persistence — new MFA devices or methods added, methods or devices removed, MFA disabled, recovery info changed, and MFA changes that look like attacker-planted persistence after a compromise.
  • MFA fatigue — waves of push prompts used to wear a user into approving.
  • Password spray & takeover — spray patterns (including named campaigns such as Storm-0940), spray attempts that flip to success, and account takeover following a spray.
  • Suspicious Temporary Access Pass issuance — TAP issued in a way consistent with attacker self-provisioning.

Business email compromise & mailbox abuse

Coverage across the Exchange Online audit surface for the classic post-compromise mailbox playbook:
  • Malicious inbox rules — rules that forward externally, hide or delete security mail, use stealthy names, or move mail to obscure folders; includes a standing sweep that re-checks existing rules and BEC-keyword matching.
  • Forwarding, transport & journal rules — external forwarding, transport-rule and journal-rule creation or removal used to siphon or intercept mail.
  • Mailbox delegation — full-access and send-as delegation granted to maintain persistent mailbox access.
  • Mail manipulation & exfiltration — bulk mail access, mass send, mass deletion, and send-then-hard-delete patterns; mailbox exfiltration that follows a token replay.
  • Audit tampering — mailbox audit logging disabled, retention policy deleted.

Microsoft Teams abuse

  • Impersonation — display-name impersonation (including fuzzy/typosquatted variants), help-desk impersonation, and onmicrosoft-domain impersonation lures.
  • External-access abuse — external guest messages, external spray, external calls and meeting joins from unknown initiators.
  • Bulk operations — bulk guest invites, bulk member adds, bulk channel deletion, and Teams used as a data-exfiltration channel.
  • Suspicious app installs — Teams apps installed in a risky context.

Endpoint & Defender signals (MDE / MDI / MDO / Entra ID Protection)

RAIDEN ingests Microsoft Defender alerts and treats them as first-class evidence, correlating them with identity and mailbox activity for the same user so an endpoint detonation and a risky sign-in land in one Case.
  • Defender for Endpoint (MDE) — credential dumping (LSASS access, hive dumps), EDR-killer driver/service activity, ransomware and mass-encryption behaviour, Cobalt Strike indicators, encoded PowerShell, LOLBin abuse, ingress tool transfer, lateral movement (PsExec, RDP-enabled-for-pivot), DNS tunnelling, Graph-based C2 beaconing, shadow-copy deletion, event-log clearing, and per-tactic Defender alert categories.
  • Defender for Identity (MDI) — reconnaissance, lateral movement, domain dominance, credential access, and honeytoken triggers.
  • Defender for Office 365 (MDO) — confirmed and suspicious malicious URLs, user URL clicks, malware, and mail-not-remediated states.
  • Entra ID Protection — risky-user and risk-detection signals folded into the same identity Case.
Defender alert ingestion uses the SecurityEvents.Read.All Graph permission, which is part of RAIDEN’s standard consented permission set. The alerts RAIDEN surfaces are the same ones in your Microsoft Defender portal — RAIDEN adds correlation and investigation on top.

Data exfiltration & destructive actions

  • SharePoint & OneDrive — mass download, mass deletion, mass anonymous-sharing-link creation, external sharing, sensitivity-label downgrades, and site-collection admin additions.
  • Document & file activity — bulk file download/delete and sync-based download/delete patterns.
  • Cloud exfiltration tooling — rclone-style cloud exfil and download cradles surfaced from endpoint telemetry.
  • Destructive impact — machine-speed bulk deletion and data-destruction behaviour.

Privilege, policy & tenant-configuration changes

  • Conditional Access — CA policy created, modified, or deleted (an attacker weakening MFA enforcement).
  • Privileged roles & PIM — privileged-group additions, direct role assignments, high-privilege PIM activations (including after-hours), PIM setting and eligibility changes, and emergency-access (break-glass) account use.
  • Cross-tenant access — cross-tenant sync and inbound cross-tenant access settings modified.
  • Exchange RBAC — admin role grants and removals.

Copilot & automation abuse

  • Microsoft 365 Copilot — high-volume Copilot usage (especially from a compromised account), organisation reconnaissance via Copilot, sensitive-file access, and prompt-injection indicators.
  • Power Platform — suspicious Power Automate flows and Power Apps activity used for data movement or persistence.

Suppressing false positives

If a detection fires on known-safe activity — a legitimate VPN you use regularly, a trusted line-of-business app — you can suppress it per IP, application, or user from the alert view. See Cases & Alerts — Marking a false positive for the steps. Suppression is targeted: suppressing one detection for one IP does not affect other detections or other IPs.