Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1485 ✕
Download CSV Show ATT&CK heatmapMassive files deletion in Microsoft SharePoint or OneDrive Informational Identity Threat Module 1 variation
A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Data Destruction (T1485)Required data: Office 365 AuditDetector tags: Data Detection & ResponseAttacker's goals: An attacker may delete files from a SaaS service to wipe data from the organization.Investigative actions: Investigate the source account and verify if it was compromised or performed an authorized activity. Review the files that were deleted to determine if they contain sensitive or critical data. Monitor the account for any further suspicious actions.Variations
Massive files deletion in Microsoft SharePoint or OneDrive with suspicious parameters
Low overridden
A suspicious user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. overridden