Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0007 ✕

Download CSV Show ATT&CK heatmap
  • Unusual access to Microsoft 365 storage services Informational Cloud 1 variation

    Unusual access was detected to a Microsoft 365 storage service.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Cloud Service Discovery (T1526)
    Required data: Azure Audit Log Microsoft Graph Logs
    Detector tags: Microsoft Graph Activity Logs
    Attacker's goals: Extract sensitive information stored in Microsoft 365 storage services.
    Investigative actions: Determine which items were accessed. Identify whether they contained any sensitive information. Check for signs of a compromised identity, such as abnormal login activity or unusual behavior. Verify if the identity is authorized to access these drives. Monitor the identity for any further suspicious actions.

    Variations

    Unusual access to Microsoft 365 storage services from an uncommon IP

    Low overridden

    Unusual access was detected to a Microsoft 365 storage service. overridden