Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1530 ✕

Download CSV Show ATT&CK heatmap
  • User accessed SaaS resource via anonymous link Informational Identity Threat Module, SaaS Threat Detection 2 variations

    A user accessed a SaaS resource via an anonymous link.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Data from Cloud Storage (T1530)
    Required data: Google Workspace Audit Logs Office 365 Audit
    Attacker's goals: An attacker is attempting to collect sensitive data.
    Investigative actions: Check the IP address from which the access originated. Examine the file that was accessed for any sensitive indicators. Follow further actions taken, such as downloading files.

    Variations

    External user accessed a sensitive SaaS file via anonymous link

    Low overridden

    An external user accessed a sensitive SaaS file via an anonymous link. overridden

    User accessed a public Google Drive document

    Informational overridden

    A user accessed a Google Drive document that is public on the web. overridden