AN1328
Analytic 1328
IaaS
Spike in object access from new IAM user or role followed by data exfiltration to external IPs
AWS:CloudTrail
GetObject, CopyObject
AWS:CloudTrail
AssumeRole
AWS:VPCFlowLogs
Unusual volume of data transferred from S3 storage endpoints to non-corporate IPs
[TimeWindow]
Timeframe for data transfer correlation (e.g., 10 minutes)
[ExternalIPAllowList]
Known list of corporate and expected outbound IP addresses
AN1329
Analytic 1329
SaaS
OAuth token granted to external app followed by download of high-volume files in OneDrive/Google Drive
m365:unified
FileAccessed, FileDownloaded, ConsentGranted
[AppRegistrationNamePattern]
Pattern of suspicious OAuth app names (e.g., `rclone`, `mega`, `backup*`)
[DownloadThresholdMB]
Flag file downloads over X MB (e.g., >100MB) within short intervals
AN1330
Analytic 1330
Office Suite
Internal user account accesses shared links outside org followed by mass file download
m365:sharepoint
AnonymousLinkCreated, FileDownloaded
azure:signinlogs
SigninSuccess
[LinkVisibilityScope]
Whether links allow anonymous/external access
[DownloadBurstThreshold]
# of files downloaded within <5 mins (e.g., >50 files)