syne0 / osprey

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches
MIT License
6 stars 2 forks source link

Exclude NT AUTHORITY\SYSTEM changes from Mailbox Permission Export in Get-OspreyTenantExchangeLogs #19

Closed syne0 closed 3 months ago

syne0 commented 4 months ago

Currently the export gets changes from NT AUTHORITY\SYSTEM which are not helpful and creates extra noise.

syne0 commented 3 months ago

If I cant figure this out by the time im ready for 1.0 to launch I'm going to cut it out and save it for 1.1 cause this is really sucking.

syne0 commented 3 months ago

ok prehaps the changes planned in #22 can actually assist with this...

syne0 commented 3 months ago

This is done!! I also export an unfiltered version just in case.