☁️
CTHFM: M365
Ctrlk
  • Welcome
  • Getting Started M365
    • Microsoft 365 Overview
    • Microsoft 365: Authentication
    • Microsoft 365 Session Times
    • Microsoft 365 Licensing
    • Microsoft 365: Tenant Setup
  • Powershell
    • Powershell Documentation
    • Powershell Basics
    • Understanding Powershell Variables
    • Understanding Cmdlets
    • Powershell Console & ISE
    • M365 Powershell Modules
      • OneDrive Powershell
      • Exchange Online Powershell
      • Sharepoint Online Powershell
      • Microsoft Graph SDK
        • Graph SDK Setup and Permission References
        • Security API
        • Common API Reference
      • Az PowerShell Purview
  • Microsoft 365: UAL
    • Unified Audit Log (UAL) Overview
    • Enable UAL
    • Audited Activities
    • Supported Services
    • UAL Schema
    • UAL Schema: Service Specific Parameters
    • Mailbox Auditing
    • Azure Monitor: M365 UAL
  • MICROSOFT 365: EXCHANGE ONLINE
    • Exchange Online
    • Common Threats
    • Exchange Online: Security Features
    • Exchange Admin Audit Logs
    • Mailbox Audit Logs
    • EOL Hunting
    • Reporting, Audit Log, Email Tracing Reference
  • Microsoft 365: OneDrive
    • OneDrive
    • OneDrive Security Architecture
    • OneDrive Common Threats
    • OneDrive and UAL
    • Key Events in OneDrive
    • OneDrive Hunting Examples
    • OneDrive Security Features
  • Microsoft 365: Sharepoint
    • Sharepoint
  • MICROSOFT 365: File Colaboration
    • File Collaboration Security Controls
    • Retention Policies and Labels
    • Information Barriers
    • Security Control References
  • Microsoft Purview
    • Purview Overview
    • Setting Up Microsoft Purview
    • Navigating the Microsoft Purview Portal
    • Data Classification
    • Sensitivity Labels
    • Purview Data Map
    • Purview Insights
    • Auditing With Purview
    • Purview Integration with Microsoft Sentinel
    • Data Lineage
    • Responding to Data Access Violations
    • Purview Licensing
    • Purview and Threat Hunting
    • Purview Insider Risk Management
    • Microsoft Purview eDiscovery
  • Microsoft Defender: Office 365
    • Licensing
    • Key Features
    • Integration Workflows
  • Microsoft Cloud App Security
    • Microsoft Cloud App Security
    • Deploying Microsoft Cloud App Security
    • Data Protection
    • Policies
    • Threat Detection
    • Azure Monitor Table Reference
  • Attack Simulator
    • Attack Simulator Overview
  • Device Management
    • Basic Mobility and Security vs Intune
    • Azure Monitor Intune Tables
  • Secure Score
    • Secure Score
    • Secure Score in Threat Hunting
    • Secure Score References
  • Defender XDR
    • Defender XDR
    • Defender XDR Licensing
    • Defender XDR Default Retention
    • Defender XDR Advanced Hunting Table Schemas
    • Automated Response Requirements
    • Supported Response Actions
  • Threat Hunting in M365
    • Threat Hunting Introduction
    • Threat Hunting Process
    • Pyramid of Pain
    • MITRE Att&ck
  • Microsoft 365 References
    • Microsoft 365 References: Good UAL Hunting
Powered by GitBook
On this page
  • Overview
  • Mail
  • User
  • Sharepoint
  • File (OneDrive)
  1. Powershell
  2. M365 Powershell Modules
  3. Microsoft Graph SDK

Common API Reference

Overview

The following is set of links to specific APIs useful in investigations.

Mail

LogoUse the Outlook mail REST API - Microsoft Graph v1.0MicrosoftLearn

User

LogoWorking with users in Microsoft Graph - Microsoft Graph v1.0MicrosoftLearn

Sharepoint

LogoWorking with SharePoint sites in Microsoft Graph - Microsoft Graph v1.0MicrosoftLearn

File (OneDrive)

LogoWorking with files in Microsoft Graph - Microsoft Graph v1.0MicrosoftLearn

PreviousSecurity APINextAz PowerShell Purview

Last updated 1 year ago