Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapUser accessed SaaS resource via anonymous link Informational Identity Threat Module, SaaS Threat Detection 2 variations
A user accessed a SaaS resource via an anonymous link.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Data from Cloud Storage (T1530)Required data: Google Workspace Audit Logs Office 365 AuditAttacker's goals: An attacker is attempting to collect sensitive data.Investigative actions: Check the IP address from which the access originated. Examine the file that was accessed for any sensitive indicators. Follow further actions taken, such as downloading files.Variations
External user accessed a sensitive SaaS file via anonymous link
Low overridden
An external user accessed a sensitive SaaS file via an anonymous link. overridden
User accessed a public Google Drive document
Informational overridden
A user accessed a Google Drive document that is public on the web. overridden