Skip to content
Threat Feed

Tag

Onedrive

5 briefs RSS
high advisory

M365 OneDrive Malware File Upload

This rule detects files uploaded to OneDrive that are identified as malware by the file scanning engine, potentially leading to lateral movement and further compromise.

OneDrive +1 cloud lateral-movement
2r 2t
medium advisory

OneDrive Share Mounted via Net Utility for Potential Data Exfiltration

Adversaries may mount OneDrive shares as network drives using net.exe or net1.exe to stage, access, or exfiltrate data through cloud-hosted WebDAV paths, potentially bypassing traditional file share monitoring.

OneDrive +3 data-exfiltration net.exe
2r 1t
medium advisory

M365 SharePoint/OneDrive File Access via PowerShell

Detects file downloads and access from OneDrive or SharePoint using PowerShell-based user agents, which adversaries leverage with compromised OAuth tokens to exfiltrate data.

Microsoft 365 +2 cloud saas microsoft365 sharepoint onedrive powershell
2r 4t
medium advisory

Entra ID Sharepoint or OneDrive Accessed by Unusual Client

An application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.

Entra ID +2 azure sharepoint onedrive oauth phishing illicit-consent
2r 4t
medium advisory

Excessive OneDrive File Downloads Detection

Detection of unusual high-volume file downloads from Microsoft OneDrive, potentially indicating data exfiltration by a compromised account or insider threat.

OneDrive data-exfiltration cloud
2r 1t