Analytics Informational

User accessed multiple O365 AIP sensitive files

A user accessed multiple O365 AIP sensitive files.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Information Repositories (T1213) Data from Local System (T1005)
Detector tags: O365 DLP Analytics
Attacker's goals:

An attacker is attempting to collect sensitive information.

Investigative actions:

Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Check what sensitivity labels are detected and how suspicious they are. Examine the user's account history for suspicious behavior.

Test period:
1 Hour
Deduplication:
1 Day