AN1580
Analytic 1580
IaaS
Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.
AWS:CloudTrail
ModifySnapshotAttribute
AWS:CloudTrail
PutBucketPolicy
AWS:CloudTrail
CreateSnapshot
AWS:CloudTrail
CopySnapshot
AWS:VPCFlowLogs
High volume internal-to-internal IP transfer or cross-account cloud transfer
[CrossAccountIDList]
List of external cloud accounts authorized for snapshot or bucket sharing
[Region]
Geographic region in which the sharing occurs (may impact logging availability)
[VolumeSizeThresholdGB]
Threshold to alert on snapshot size or object volume
[TimeWindow]
Temporal window between snapshot creation and external sharing
AN1581
Analytic 1581
Office Suite
Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.
m365:unified
SharingSet
m365:unified
AnonymousLinkCreated
m365:unified
FileAccessed
[ExternalDomainList]
Known partner or adversarial cloud identities/domains
[TimeWindow]
Duration between file access and external sharing
[SharingMethod]
Type of link (anonymous, internal, organization-wide) to alert on
AN1582
Analytic 1582
SaaS
Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.
saas:googledrive
drive.permission.add
saas:box
collaboration.invite
[UserContext]
Whether the user is in a high-privileged or VIP group
[DomainReputationList]
Allowlist or blocklist of external SaaS domains
[PayloadVolumeThreshold]
Size or number of shared files triggering alert