Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • External SaaS file-sharing activity Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A user shared files from within a SaaS service to an external domain.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Data from Cloud Storage (T1530)
    Required data: Box Audit Log DropBox Google Workspace Audit Logs Office 365 Audit
    Detector tags: Data Detection & Response
    Attacker's goals: An attacker may share files from a SaaS service to exfiltrate sensitive data.
    Investigative actions: Check for signs of account compromise, such as abnormal login activity or unusual behavior. Determine if the files are shared with users outside the organization and if the recipients are familiar. Review the files that were shared to determine if they contain sensitive data. Analyze the file types that were shared. Monitor the account for any further suspicious actions.

    Variations

    SaaS external file sharing to an abnormal domain

    Low overridden

    A user shared files to an external domain, which the organization does not typically share files with. overridden