Analytics Informational

Uncommon increase in Azure Microsoft Graph API request sizes

An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:

Exfiltrate data over Microsoft Graph API.

Investigative actions:

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

Test period:
10 Minutes
Deduplication:
5 Days
3 variations:
  • Unusual Azure high-volume data transfer Medium (parent: Informational)
  • Suspicious Azure data transfer by identity Medium (parent: Informational)
  • Unusual data transfer from multiple Azure tenants Low (parent: Informational)