> ## Documentation Index
> Fetch the complete documentation index at: https://docs.raidenhq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# RAIDEN detection coverage: M365 threat detections

> What RAIDEN detects across Microsoft 365 — identity and AiTM, business email compromise, OAuth consent abuse, device-code phishing, Teams abuse, Defender endpoint signals, and data exfiltration.

RAIDEN runs a large library of purpose-built detections against your Microsoft 365 activity continuously. Each detection targets a specific attack technique or abuse pattern seen in real M365 environments. This page describes what RAIDEN covers, grouped by attack category, and how findings turn into investigations.

RAIDEN ships **269 detection rules** in total — **145 detections** (each can open or escalate a Case) and **124 signals** (enrichment evidence that strengthens an existing Case). You don't manage these individually; RAIDEN evaluates all of them automatically and only surfaces what matters as a Case.

## How detections work

RAIDEN ingests Microsoft 365 activity on a continuous poll cycle and evaluates it against the full detection library. Identity sign-in activity is polled on a fast cadence — roughly every **2 minutes** — so account-takeover signals surface quickly. Other workloads (mailbox, SharePoint, Teams, Defender alerts) are polled on their own cadences.

When a detection's conditions are met, a finding is created. Related findings for the same user are grouped into a **Case** with an AI-generated investigation report that lays out what happened, the supporting evidence, and a recommended verdict. Lower-weight **signals** attach to that Case as corroborating evidence rather than opening Cases of their own.

Detections are:

* **Per-user scoped** — findings are attributed to a specific user account, so a Case reads as a coherent story about one identity.
* **Evidence-layered** — a Case combines high-confidence detections with supporting signals across multiple Microsoft data sources rather than relying on any single indicator.
* **Tunable via suppression** — if a detection fires on known-safe activity, you can suppress it per IP, application, or user. See [Cases & Alerts — Suppression](/cases-and-alerts#suppression-options).

***

## Identity, sessions & AiTM

The largest part of RAIDEN's coverage. RAIDEN reconstructs each user's authentication sessions from Entra ID sign-in activity and looks for the hallmarks of account takeover and adversary-in-the-middle (AiTM) phishing.

What this covers:

* **AiTM phishing** — sign-in patterns and infrastructure consistent with token-stealing reverse proxies, including fingerprint matches against known phishing-as-a-service kits (FlowerStorm, Tycoon 2FA, EvilProxy, Mamba 2FA and variants).
* **Token theft & session hijacking** — the same session reused from a different origin, replayed or unbound tokens, and tokens minted from suspicious infrastructure.
* **Impossible travel & geo anomalies** — successful sign-ins from locations too far apart to be physically possible in the elapsed time, and sudden geographic spread within one session.
* **Suspicious sign-in infrastructure** — sign-ins from networks associated with attacker hosting, anonymising proxies, consumer VPNs, and residential-proxy services, scored by reputation tier rather than treated as an automatic verdict.
* **Behavioural baseline deviations** — once RAIDEN has learned a user's normal pattern, it flags first-time countries, unusual sign-in hours, new device or user-agent families, and login-frequency spikes.

These run together so a single compromised session is assembled from many corroborating pieces of evidence rather than one noisy alert.

***

## Phishing & token-grab techniques

Detections for the specific ways attackers trick a user into handing over access:

* **Device-code phishing** — abuse of the OAuth device-code flow to capture a refresh token without ever needing the victim's password, including detection of completed device-code token theft and device-code use that deviates from the user's baseline.
* **Phishing-kit infrastructure matches** — sign-ins from IPs and infrastructure tied to known AiTM kits and credential-stuffing campaigns, matched against a continuously maintained threat-intel set.
* **Malicious URL clicks** — confirmed and suspicious malicious-link clicks surfaced from Microsoft Defender for Office 365.
* **Forms-based phishing** — Microsoft Forms used as a credential-harvesting lure.

***

## OAuth & application consent abuse

Attackers increasingly persist through OAuth apps rather than stolen passwords. RAIDEN watches the consent and app-registration surface:

* **Suspicious consent grants** — OAuth consent to apps requesting high-privilege scopes, apps with suspicious names, or consent that immediately follows a risky sign-in.
* **Known-abused applications** — consent to apps already associated with abuse.
* **App-registration & credential abuse** — new app registrations, injection of credentials onto an existing app, federated-credential additions, silent scope expansion, app-role escalation, and localhost-redirect patterns consistent with C2 callbacks.
* **Fast identity-to-OAuth pivots** — a compromised identity granting an OAuth app moments after takeover.

***

## MFA, password & credential attacks

* **MFA tampering & persistence** — new MFA devices or methods added, methods or devices removed, MFA disabled, recovery info changed, and MFA changes that look like attacker-planted persistence after a compromise.
* **MFA fatigue** — waves of push prompts used to wear a user into approving.
* **Password spray & takeover** — spray patterns (including named campaigns such as Storm-0940), spray attempts that flip to success, and account takeover following a spray.
* **Suspicious Temporary Access Pass issuance** — TAP issued in a way consistent with attacker self-provisioning.

***

## Business email compromise & mailbox abuse

Coverage across the Exchange Online audit surface for the classic post-compromise mailbox playbook:

* **Malicious inbox rules** — rules that forward externally, hide or delete security mail, use stealthy names, or move mail to obscure folders; includes a standing sweep that re-checks existing rules and BEC-keyword matching.
* **Forwarding, transport & journal rules** — external forwarding, transport-rule and journal-rule creation or removal used to siphon or intercept mail.
* **Mailbox delegation** — full-access and send-as delegation granted to maintain persistent mailbox access.
* **Mail manipulation & exfiltration** — bulk mail access, mass send, mass deletion, and send-then-hard-delete patterns; mailbox exfiltration that follows a token replay.
* **Audit tampering** — mailbox audit logging disabled, retention policy deleted.

***

## Microsoft Teams abuse

* **Impersonation** — display-name impersonation (including fuzzy/typosquatted variants), help-desk impersonation, and onmicrosoft-domain impersonation lures.
* **External-access abuse** — external guest messages, external spray, external calls and meeting joins from unknown initiators.
* **Bulk operations** — bulk guest invites, bulk member adds, bulk channel deletion, and Teams used as a data-exfiltration channel.
* **Suspicious app installs** — Teams apps installed in a risky context.

***

## Endpoint & Defender signals (MDE / MDI / MDO / Entra ID Protection)

RAIDEN ingests Microsoft Defender alerts and treats them as first-class evidence, correlating them with identity and mailbox activity for the same user so an endpoint detonation and a risky sign-in land in one Case.

* **Defender for Endpoint (MDE)** — credential dumping (LSASS access, hive dumps), EDR-killer driver/service activity, ransomware and mass-encryption behaviour, Cobalt Strike indicators, encoded PowerShell, LOLBin abuse, ingress tool transfer, lateral movement (PsExec, RDP-enabled-for-pivot), DNS tunnelling, Graph-based C2 beaconing, shadow-copy deletion, event-log clearing, and per-tactic Defender alert categories.
* **Defender for Identity (MDI)** — reconnaissance, lateral movement, domain dominance, credential access, and honeytoken triggers.
* **Defender for Office 365 (MDO)** — confirmed and suspicious malicious URLs, user URL clicks, malware, and mail-not-remediated states.
* **Entra ID Protection** — risky-user and risk-detection signals folded into the same identity Case.

<Note>
  Defender alert ingestion uses the `SecurityEvents.Read.All` Graph permission, which is part of RAIDEN's standard consented permission set. The alerts RAIDEN surfaces are the same ones in your Microsoft Defender portal — RAIDEN adds correlation and investigation on top.
</Note>

***

## Data exfiltration & destructive actions

* **SharePoint & OneDrive** — mass download, mass deletion, mass anonymous-sharing-link creation, external sharing, sensitivity-label downgrades, and site-collection admin additions.
* **Document & file activity** — bulk file download/delete and sync-based download/delete patterns.
* **Cloud exfiltration tooling** — rclone-style cloud exfil and download cradles surfaced from endpoint telemetry.
* **Destructive impact** — machine-speed bulk deletion and data-destruction behaviour.

***

## Privilege, policy & tenant-configuration changes

* **Conditional Access** — CA policy created, modified, or deleted (an attacker weakening MFA enforcement).
* **Privileged roles & PIM** — privileged-group additions, direct role assignments, high-privilege PIM activations (including after-hours), PIM setting and eligibility changes, and emergency-access (break-glass) account use.
* **Cross-tenant access** — cross-tenant sync and inbound cross-tenant access settings modified.
* **Exchange RBAC** — admin role grants and removals.

***

## Copilot & automation abuse

* **Microsoft 365 Copilot** — high-volume Copilot usage (especially from a compromised account), organisation reconnaissance via Copilot, sensitive-file access, and prompt-injection indicators.
* **Power Platform** — suspicious Power Automate flows and Power Apps activity used for data movement or persistence.

***

## Suppressing false positives

If a detection fires on known-safe activity — a legitimate VPN you use regularly, a trusted line-of-business app — you can suppress it per IP, application, or user from the alert view. See [Cases & Alerts — Marking a false positive](/cases-and-alerts#marking-a-false-positive) for the steps.

Suppression is targeted: suppressing one detection for one IP does not affect other detections or other IPs.
