Analytics
Low
✕
Microsoft 365 storage services exfiltration activity
The Microsoft Graph API was used to download Microsoft OneDrive and SharePoint files.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Cloud Storage (T1530)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:
To extract sensitive information stored in Microsoft 365 storage services.
Investigative actions:
Determine which items were downloaded and whether they contained any sensitive information. Investigate the identity following actions.
- Test period:
- 10 Minutes
- Deduplication:
- 5 Days