Analytics BIOC
Informational
✕
OneDrive file upload
A file was uploaded to OneDrive using Microsoft Graph API.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Resource Development (TA0042)
ATT&CK techniques: Stage Capabilities (T1608) Stage Capabilities: Upload Malware (T1608.001)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:
Establish persistence by uploading files to OneDrive, potentially using it as a staging area for further malicious activities.
Investigative actions:
Look for any unusual behavior originated from the suspected identity, and check if they're compromised.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days