Tag
M365 OneDrive Malware File Upload
2 rules 2 TTPsThis rule detects files uploaded to OneDrive that are identified as malware by the file scanning engine, potentially leading to lateral movement and further compromise.
OneDrive Share Mounted via Net Utility for Potential Data Exfiltration
2 rules 1 TTPAdversaries may mount OneDrive shares as network drives using net.exe or net1.exe to stage, access, or exfiltrate data through cloud-hosted WebDAV paths, potentially bypassing traditional file share monitoring.
M365 SharePoint/OneDrive File Access via PowerShell
2 rules 4 TTPsDetects file downloads and access from OneDrive or SharePoint using PowerShell-based user agents, which adversaries leverage with compromised OAuth tokens to exfiltrate data.
Entra ID Sharepoint or OneDrive Accessed by Unusual Client
2 rules 4 TTPsAn application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.
Excessive OneDrive File Downloads Detection
2 rules 1 TTPDetection of unusual high-volume file downloads from Microsoft OneDrive, potentially indicating data exfiltration by a compromised account or insider threat.