Analytics
Informational
✕
Uncommon increase in Azure Microsoft Graph API request sizes
An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:
Exfiltrate data over Microsoft Graph API.
Investigative actions:
Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.
- Test period:
- 10 Minutes
- Deduplication:
- 5 Days
3 variations:
- Unusual Azure high-volume data transfer Medium (parent: Informational)
- Suspicious Azure data transfer by identity Medium (parent: Informational)
- Unusual data transfer from multiple Azure tenants Low (parent: Informational)