Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0007 ✕ technique: T1526 ✕
Download CSV Show ATT&CK heatmapUnusual access to Microsoft 365 storage services Informational Cloud 1 variation
Unusual access was detected to a Microsoft 365 storage service.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Cloud Service Discovery (T1526)Required data: Azure Audit Log Microsoft Graph LogsDetector tags: Microsoft Graph Activity LogsAttacker's goals: Extract sensitive information stored in Microsoft 365 storage services.Investigative actions: Determine which items were accessed. Identify whether they contained any sensitive information. Check for signs of a compromised identity, such as abnormal login activity or unusual behavior. Verify if the identity is authorized to access these drives. Monitor the identity for any further suspicious actions.Variations
Unusual access to Microsoft 365 storage services from an uncommon IP
Low overridden
Unusual access was detected to a Microsoft 365 storage service. overridden