Analytics BIOC Informational

SharePoint Site Collection admin group addition

A user made an addition to the site collection administrators group in SharePoint.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Office 365 Audit
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003)
Attacker's goals:

Elevate permissions and establish persistence.

Investigative actions:

Check the IP address from which the access originated. Verify the activity with the performing user. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • SharePoint site collection admin added to personal site Informational
  • Abnormal SharePoint Site Collection admin group addition Low (parent: Informational)