Analytics
Informational
✕
Microsoft OneNote enumeration activity
The Microsoft Graph API was used to enumerate Microsoft OneNote items.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Service Discovery (T1526)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:
To extract sensitive information stored in Microsoft OneNote.
Investigative actions:
Determine which OneNote items were enumerated and whether they contained any sensitive information. Investigate the identity following actions.
- Test period:
- 10 Minutes
- Deduplication:
- 5 Days