Analytics
Informational
✕
External SaaS file-sharing activity
A user shared files from within a SaaS service to an external domain.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Cloud Storage (T1530)
Detector tags: Data Detection & Response
Attacker's goals:
An attacker may share files from a SaaS service to exfiltrate sensitive data.
Investigative actions:
Check for signs of account compromise, such as abnormal login activity or unusual behavior. Determine if the files are shared with users outside the organization and if the recipients are familiar. Review the files that were shared to determine if they contain sensitive data. Analyze the file types that were shared. Monitor the account for any further suspicious actions.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day
1 variation:
- SaaS external file sharing to an abnormal domain Low (parent: Informational)