Analytics Informational

Massive files deletion in Dropbox

A user deleted a large amount of data in Dropbox. This behavior may indicate that the data is being wiped.

Module:
Identity Threat Detection (ITDR)
Licensed by:
Identity Threat Detection (ITDR)
Data source:
DropBox
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Data Destruction (T1485)
Detector tags: Data Detection & Response
Attacker's goals:

An attacker may delete files from a SaaS service to wipe data from the organization.

Investigative actions:

Investigate the source account and verify if it was compromised or performed an authorized activity. Review the files that were deleted to determine if they contain sensitive or critical data. Monitor the account for any further suspicious actions.

Test period:
1 Hour
Deduplication:
1 Day
1 variation:
  • Massive files deletion in Dropbox with suspicious parameters Low (parent: Informational)