GithubHelp home page GithubHelp logo

Comments (6)

DeemOnSecurity avatar DeemOnSecurity commented on August 17, 2024 1

Interesting, perhaps we need to add a switch to disable the O365 check

from sparrow.

genericdevname avatar genericdevname commented on August 17, 2024

Maybe I'm misreading the issue, but what if you comment out line 475:
Get-UALData -ExportDir $ExportDir -StartDate $StartDate -EndDate $EndDate -ExchangeEnvironment $ExchangeEnvironment -AzureEnvironment $AzureEnvironment -Verbose

Do you still receive the error?

from sparrow.

dvp420 avatar dvp420 commented on August 17, 2024

I don't think you're misreading the issue. I commented line 475 and re-ran and got the export files successfully generated. I had attempted to identify which line(s) would be required...but #notadev. Thanks! I still think it would be an improvement to have a switch but simply adding this to the documentation would also be sufficient. I'm closing the issue.

from sparrow.

dvp420 avatar dvp420 commented on August 17, 2024

Perhaps I closed too soon without verifying what the output results should be after commenting out 475. In my scenario, I only got two .csv files. ApplicationGraphPermissions.csv and Domain_list.csv.

What I don't have, and perhaps it's a good sign, is that there's no files for AppRoleAssignment_Operations_Export.csv, AppUpdate_Operations_Export.csv, Consent_Operations_Export.csv, Domain_Operations_Export.csv,PSLogin_Operations_Export.csv,SAMLToken_Operations_Export.csv,ServicePrincipal_Operations_Export.csv

from sparrow.

genericdevname avatar genericdevname commented on August 17, 2024

Thank you for clarifying. Sparrow relies on being able to look at the unified audit log of a tenant organization, which is part of the Exchange Online PowerShell cmdlets (https://docs.microsoft.com/en-us/powershell/module/exchange/search-unifiedauditlog?view=exchange-ps).

Without Exchange Online, you will only receive those two .csv files.

from sparrow.

dvp420 avatar dvp420 commented on August 17, 2024

Thanks for the clarification. And those two files are pretty benign in what they're going to show. the UAL stuff is really where the IOC or other unknown activities to be investigated would be.

from sparrow.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.