M365 SharePoint/OneDrive File Access via PowerShell
Identifies file downloads or access from OneDrive or SharePoint using PowerShell-based user agents. Adversaries may use native PowerShell cmdlets like Invoke-WebRequest or Invoke-RestMethod with Microsoft Graph API to exfiltrate data after compromising OAuth tokens via device code phishing or other credential theft techniques. This rule detects both direct PowerShell access and PnP PowerShell module usage for file operations. FileAccessed events are included to detect adversaries reading file content via API and saving locally, bypassing traditional download methods. Normal users access SharePoint/OneDrive via browsers or sync clients, making PowerShell-based file access inherently suspicious.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/02/24"
3integration = ["o365"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Identifies file downloads or access from OneDrive or SharePoint using PowerShell-based user agents. Adversaries may use
11native PowerShell cmdlets like Invoke-WebRequest or Invoke-RestMethod with Microsoft Graph API to exfiltrate data after
12compromising OAuth tokens via device code phishing or other credential theft techniques. This rule detects both direct
13PowerShell access and PnP PowerShell module usage for file operations. FileAccessed events are included to detect
14adversaries reading file content via API and saving locally, bypassing traditional download methods. Normal users access
15SharePoint/OneDrive via browsers or sync clients, making PowerShell-based file access inherently suspicious.
16"""
17false_positives = [
18 "Legitimate automation scripts using PowerShell to interact with SharePoint or OneDrive for business purposes.",
19 "IT administrators using PnP PowerShell for site management, migration, or backup operations.",
20]
21from = "now-9m"
22index = ["filebeat-*", "logs-o365.audit-*"]
23language = "kuery"
24license = "Elastic License v2"
25name = "M365 SharePoint/OneDrive File Access via PowerShell"
26note = """## Triage and Analysis
27
28### Investigating M365 SharePoint/OneDrive File Access via PowerShell
29
30This rule detects file downloads and access from OneDrive or SharePoint using PowerShell-based user agents. Threat actors commonly use device code phishing to obtain OAuth tokens, then use native PowerShell or PnP PowerShell modules to enumerate and exfiltrate files from SharePoint and OneDrive. FileAccessed events are included because adversaries may read file content via the Graph API `/content` endpoint and save locally, bypassing traditional download events.
31
32#### Possible Investigation Steps
33
34- Identify the user whose token was used and determine if they typically use PowerShell for file operations.
35- Review the OAuth application/client ID used to authenticate. Look for public client IDs that may indicate device code phishing.
36- Check the source IP address and compare with the user's typical access locations.
37- Identify which SharePoint site or OneDrive was accessed.
38- Correlate with Azure AD sign-in logs to determine if device code authentication was used.
39- Look for rapid sequential file downloads from the same session, which may indicate bulk data exfiltration.
40- Check for search activity from the same user/session that may indicate reconnaissance before download.
41
42### False Positive Analysis
43
44- IT administrators legitimately using PnP PowerShell for site management, migration, or backup operations.
45- Automated scripts using PowerShell for legitimate data processing or synchronization tasks.
46- Consider creating exceptions for known automation service accounts.
47
48### Response and Remediation
49
50- If unauthorized activity is confirmed, immediately revoke the OAuth token and terminate active sessions for the affected user.
51- Reset the user's credentials and require reauthentication with MFA.
52- Review all files accessed during the session to assess data exposure.
53- Implement conditional access policies to restrict device code authentication flow.
54- Consider blocking public client IDs that are not needed for business operations.
55- Review and audit OAuth application permissions in your tenant.
56"""
57references = [
58 "https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/",
59 "https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft",
60 "https://pnp.github.io/powershell/",
61]
62risk_score = 73
63rule_id = "491651da-125b-11f1-af7d-f661ea17fbce"
64severity = "high"
65tags = [
66 "Domain: Cloud",
67 "Domain: SaaS",
68 "Data Source: Microsoft 365",
69 "Data Source: Microsoft 365 Audit Logs",
70 "Use Case: Threat Detection",
71 "Tactic: Collection",
72 "Tactic: Exfiltration",
73 "Resources: Investigation Guide",
74 "Noise: Medium",
75 "Performance: Normal",
76 "Rule Type: New Terms",
77 "Platform: Microsoft 365",
78 "Domain: Email",
79 "Service: Microsoft SharePoint",
80 "Service: Microsoft OneDrive",
81]
82timestamp_override = "event.ingested"
83type = "new_terms"
84
85query = '''
86data_stream.dataset: "o365.audit" and
87 event.provider: ("SharePoint" or "OneDrive") and
88 event.action: ("FileDownloaded" or "FileAccessed") and
89 event.outcome: "success" and
90 user_agent.original: (*PowerShell* or *PnPPS* or *PnPCoreSDK* or *SharePointPnP*)
91'''
92
93
94[[rule.threat]]
95framework = "MITRE ATT&CK"
96
97[[rule.threat.technique]]
98id = "T1213"
99name = "Data from Information Repositories"
100reference = "https://attack.mitre.org/techniques/T1213/"
101
102[[rule.threat.technique.subtechnique]]
103id = "T1213.002"
104name = "Sharepoint"
105reference = "https://attack.mitre.org/techniques/T1213/002/"
106
107[[rule.threat.technique]]
108id = "T1530"
109name = "Data from Cloud Storage"
110reference = "https://attack.mitre.org/techniques/T1530/"
111
112[rule.threat.tactic]
113id = "TA0009"
114name = "Collection"
115reference = "https://attack.mitre.org/tactics/TA0009/"
116
117[[rule.threat]]
118framework = "MITRE ATT&CK"
119
120[rule.threat.tactic]
121id = "TA0010"
122name = "Exfiltration"
123reference = "https://attack.mitre.org/tactics/TA0010/"
124
125[[rule.threat]]
126framework = "MITRE ATT&CK"
127
128[[rule.threat.technique]]
129id = "T1059"
130name = "Command and Scripting Interpreter"
131reference = "https://attack.mitre.org/techniques/T1059/"
132
133[[rule.threat.technique.subtechnique]]
134id = "T1059.001"
135name = "PowerShell"
136reference = "https://attack.mitre.org/techniques/T1059/001/"
137
138[rule.threat.tactic]
139id = "TA0002"
140name = "Execution"
141reference = "https://attack.mitre.org/tactics/TA0002/"
142
143[rule.investigation_fields]
144field_names = [
145 "@timestamp",
146 "user.id",
147 "user_agent.original",
148 "event.action",
149 "event.provider",
150 "source.ip",
151 "source.geo.country_name",
152 "o365.audit.ApplicationId",
153 "o365.audit.SiteUrl",
154 "file.name",
155 "file.directory",
156]
157
158[rule.new_terms]
159field = "new_terms_fields"
160value = ["user.id", "user_agent.original"]
161[[rule.new_terms.history_window_start]]
162field = "history_window_start"
163value = "now-7d"
Triage and Analysis
Investigating M365 SharePoint/OneDrive File Access via PowerShell
This rule detects file downloads and access from OneDrive or SharePoint using PowerShell-based user agents. Threat actors commonly use device code phishing to obtain OAuth tokens, then use native PowerShell or PnP PowerShell modules to enumerate and exfiltrate files from SharePoint and OneDrive. FileAccessed events are included because adversaries may read file content via the Graph API /content endpoint and save locally, bypassing traditional download events.
Possible Investigation Steps
- Identify the user whose token was used and determine if they typically use PowerShell for file operations.
- Review the OAuth application/client ID used to authenticate. Look for public client IDs that may indicate device code phishing.
- Check the source IP address and compare with the user's typical access locations.
- Identify which SharePoint site or OneDrive was accessed.
- Correlate with Azure AD sign-in logs to determine if device code authentication was used.
- Look for rapid sequential file downloads from the same session, which may indicate bulk data exfiltration.
- Check for search activity from the same user/session that may indicate reconnaissance before download.
False Positive Analysis
- IT administrators legitimately using PnP PowerShell for site management, migration, or backup operations.
- Automated scripts using PowerShell for legitimate data processing or synchronization tasks.
- Consider creating exceptions for known automation service accounts.
Response and Remediation
- If unauthorized activity is confirmed, immediately revoke the OAuth token and terminate active sessions for the affected user.
- Reset the user's credentials and require reauthentication with MFA.
- Review all files accessed during the session to assess data exposure.
- Implement conditional access policies to restrict device code authentication flow.
- Consider blocking public client IDs that are not needed for business operations.
- Review and audit OAuth application permissions in your tenant.
References
Related rules
- M365 OneDrive/SharePoint Excessive File Downloads
- M365 Exchange Mailbox Accessed by Unusual Client
- M365 Identity Device Code Grant by an Unusual User (Non-Compliant Device)
- M365 SharePoint Search for Sensitive Content
- M365 Exchange Inbox Forwarding Rule Created