Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0500 — Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users
DET0500

Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1380 Analytic 1380
Windows

Privileged or rarely used accounts performing bulk access to SharePoint files or metadata over a short time window, indicating potential scripted collection of sensitive internal documents.

m365:unified FileAccessed, FileDownloaded, SearchQueried azure:signinlogs UserLogin, ConditionalAccessPolicyEvaluated m365:sharepoint Multiple file download operations on a site by a privileged account in a short time window
[UserContext] Can be adjusted to focus on specific high-privilege or rarely-used service accounts
[TimeWindow] Defines the aggregation period for multiple download events (e.g., 10 minutes)
[DownloadThreshold] Minimum number of documents accessed/downloaded to trigger alert
[SiteScope] Limit detection to sensitive SharePoint sites such as HR, Finance, Engineering

Detected Techniques

1

Collection (1)

Details

MITRE ID
DET0500
STIX ID
x-mitre-detection-strategy--960d6663-6a7f-4f95-affe-a28d71afc7d9
Analytics
1
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.