Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0484 — Multi-Platform Cloud Storage Exfiltration Behavior Chain
DET0484

Multi-Platform Cloud Storage Exfiltration Behavior Chain

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1328 Analytic 1328
IaaS

Spike in object access from new IAM user or role followed by data exfiltration to external IPs

AWS:CloudTrail GetObject, CopyObject AWS:CloudTrail AssumeRole AWS:VPCFlowLogs Unusual volume of data transferred from S3 storage endpoints to non-corporate IPs
[TimeWindow] Timeframe for data transfer correlation (e.g., 10 minutes)
[ExternalIPAllowList] Known list of corporate and expected outbound IP addresses
AN1329 Analytic 1329
SaaS

OAuth token granted to external app followed by download of high-volume files in OneDrive/Google Drive

m365:unified FileAccessed, FileDownloaded, ConsentGranted
[AppRegistrationNamePattern] Pattern of suspicious OAuth app names (e.g., `rclone`, `mega`, `backup*`)
[DownloadThresholdMB] Flag file downloads over X MB (e.g., >100MB) within short intervals
AN1330 Analytic 1330
Office Suite

Internal user account accesses shared links outside org followed by mass file download

m365:sharepoint AnonymousLinkCreated, FileDownloaded azure:signinlogs SigninSuccess
[LinkVisibilityScope] Whether links allow anonymous/external access
[DownloadBurstThreshold] # of files downloaded within <5 mins (e.g., >50 files)

Detected Techniques

1

Details

MITRE ID
DET0484
STIX ID
x-mitre-detection-strategy--1177cbb7-bc00-4a36-8774-d51b7b3c66e9
Analytics
3
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.