Analytics
Low
✕
A user uploaded malware to SharePoint or OneDrive
A user uploaded a file that was classified as malware to SharePoint or OneDrive.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Office 365 Audit
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: Taint Shared Content (T1080) User Execution: Malicious File (T1204.002)
Detector tags: Data Detection & Response
Attacker's goals:
An attacker may upload malware to a shared location to gain execution and move laterally.
Investigative actions:
Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check the file that was uploaded for any malicious indicators. Follow further actions done by the account.
- Test period:
- 3 Hours
- Deduplication:
- 1 Day
2 variations:
- A user uploaded malware to SharePoint or OneDrive with suspicious characteristics Medium (parent: Low)
- A user uploaded a malicious payload to SharePoint or OneDrive Informational (parent: Low)