Try in Splunk SOAR

Description

Accepts message ID that needs to be restored to the provided email mailbox in Microsoft Office365. Generates an observable output based on the status of message restoration.

  • Type: Response
  • Product: Splunk SOAR
  • Apps: MS Graph for Office 365
  • Last Updated: 2024-02-15
  • Author: Lou Stella, Splunk
  • ID: 5299d6dd-e9c4-4bad-b041-928ace1ff811
  • Use-cases:
    • Phishing

Associated Detections

How To Implement

This input playbook requires the MS Graph for Office 365 connector to be configured.

D3FEND

ID Technique Definition Category
D3-RE Restore Email Restoring a file for an entity to access. Restore Object

Explore Playbook

explore

Required field

Reference

source | version: 1