Analytics BIOC Informational

User accessed SaaS resource via anonymous link

A user accessed a SaaS resource via an anonymous link.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs, Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Cloud Storage (T1530)
Attacker's goals:

An attacker is attempting to collect sensitive data.

Investigative actions:

Check the IP address from which the access originated. Examine the file that was accessed for any sensitive indicators. Follow further actions taken, such as downloading files.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • External user accessed a sensitive SaaS file via anonymous link Low (parent: Informational)
  • User accessed a public Google Drive document Informational