Analytics BIOC Informational

Rare DLP rule match by user

A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Information Repositories: Sharepoint (T1213.002) Data from Information Repositories (T1213)
Detector tags: O365 DLP Analytics
Attacker's goals:

An attacker is attempting to access sensitive information.

Investigative actions:

Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • DLP rule match by user for the first time Low (parent: Informational)