Analytics Informational

Massive file downloads from SaaS service

A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Cloud Storage (T1530)
Detector tags: Data Detection & Response
Attacker's goals:

An attacker may download files from a SaaS service to exfiltrate sensitive data.

Investigative actions:

Check for signs of account compromise, such as abnormal login activity or unusual behavior. Review the files that were downloaded to determine if they contain sensitive data. Verify if the user account that downloaded the files is authorized to access them. Analyze the file types that were downloaded. Monitor the account for any further suspicious actions.

Test period:
1 Hour
Deduplication:
1 Day
3 variations:
  • Suspicious SaaS service file downloads Low (parent: Informational)
  • Massive file downloads from SaaS service by terminated user Low (parent: Informational)
  • Massive code file downloads from SaaS service Low (parent: Informational)