Analytics BIOC
Informational
✕
Unusual access to Microsoft 365 storage services
Unusual access was detected to a Microsoft 365 storage service.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Service Discovery (T1526)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:
Extract sensitive information stored in Microsoft 365 storage services.
Investigative actions:
Determine which items were accessed. Identify whether they contained any sensitive information. Check for signs of a compromised identity, such as abnormal login activity or unusual behavior. Verify if the identity is authorized to access these drives. Monitor the identity for any further suspicious actions.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
1 variation:
- Unusual access to Microsoft 365 storage services from an uncommon IP Low (parent: Informational)