Payroll Pirate: Microsoft Graph API Bulk HR/Payroll Directory Enumeration
Detects high-volume, potentially automated enumeration of Microsoft Graph API endpoints targeting sensitive personnel data (payroll, HR, finance). This rule identifies requests using non-standard or suspicious user agents—such as curl, python-requests, or common web client patterns—when interacting with user and group directories in the Microsoft 365 environment, characteristic of the 'Payroll Pirate' (Storm-2755/Storm-2657) campaign patterns.
Cortex XDR

