Techniques › T1648 › AN1054
AN1054 Analytic 1054
Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Monitor for creation of new Power Automate flows or equivalent automation scripts that trigger on user or file events. Detect anomalous actions performed by these automations, such as email forwarding, anonymous link creation, or unexpected API calls to external endpoints.</p>
- Detects
- T1648 Serverless Execution
- Part of
- DET0374 Detection Strategy for Serverless Execution (T1648)
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| m365:unified | AddFlow / UpdateFlow: New automation or workflow creation events | DC0069 Cloud Service Modification |
| m365:exchange | New-InboxRule: Automation that triggers abnormal forwarding or external link generation | DC0038 Application Log Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
UserContext | Business units or users where automation creation is expected (developers, admins) |
FlowActions | Specific automation actions (email forwarding, file sharing) that should be considered suspicious |