Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0009 ✕
Download CSV Show ATT&CK heatmapUser accessed multiple O365 AIP sensitive files Informational Identity Threat Module, SaaS Threat Detection
A user accessed multiple O365 AIP sensitive files.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Data from Information Repositories (T1213) Data from Local System (T1005)Required data: Office 365 AuditDetector tags: O365 DLP AnalyticsAttacker's goals: An attacker is attempting to collect sensitive information.Investigative actions: Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Check what sensitivity labels are detected and how suspicious they are. Examine the user's account history for suspicious behavior.