-
Entra ID Sharepoint or OneDrive Accessed by Unusual Client
Sep 19, 2026 · Domain: Cloud Domain: Identity Domain: Storage Use Case: Identity and Access Audit Tactic: Collection Tactic: Initial Access Data Source: Azure Data Source: Microsoft Entra ID Data Source: Microsoft Entra ID Sign-In Logs Resources: Investigation Guide Rule Type: New Terms Noise: Medium Performance: Fast Platform: Entra ID Platform: Azure Service: Microsoft SharePoint Service: Microsoft OneDrive ·Identifies when an application accesses SharePoint Online or OneDrive for Business for the first time in the tenant within a specified timeframe. This detects successful OAuth phishing campaigns, illicit consent grants, or compromised third-party applications gaining initial access to file storage. Adversaries often use malicious OAuth applications or phishing techniques to gain consent from users, allowing persistent access to organizational data repositories without traditional credential theft.
Read More -
Identifies the occurrence of files uploaded to OneDrive being detected as Malware by the file scanning engine. Attackers can use File Sharing and Organization Repositories to spread laterally within the company and amplify their access. Users can inadvertently share these files without knowing their maliciousness, giving adversaries an opportunity to gain initial access to other endpoints in the environment.
Read More -
M365 OneDrive/SharePoint Excessive File Downloads
Sep 19, 2026 · Domain: Cloud Domain: SaaS Domain: Storage Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Data Source: SharePoint Data Source: OneDrive Use Case: Threat Detection Tactic: Collection Tactic: Exfiltration Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: ES|QL Platform: Microsoft 365 Domain: Email Service: Microsoft SharePoint Service: Microsoft OneDrive ·Identifies when an excessive number of files are downloaded from OneDrive or SharePoint by an authorized user or application in a short period of time. This may indicate a potential data exfiltration event, especially if the downloads are performed using OAuth authentication which could suggest an OAuth phishing attack such as Device Code Authentication phishing.
Read More -
M365 SharePoint/OneDrive File Access via PowerShell
Sep 19, 2026 · Domain: Cloud Domain: SaaS Data Source: Microsoft 365 Data Source: Microsoft 365 Audit Logs Use Case: Threat Detection Tactic: Collection Tactic: Exfiltration Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: New Terms Platform: Microsoft 365 Domain: Email Service: Microsoft SharePoint Service: Microsoft OneDrive ·Identifies file downloads or access from OneDrive or SharePoint using PowerShell-based user agents. Adversaries may use native PowerShell cmdlets like Invoke-WebRequest or Invoke-RestMethod with Microsoft Graph API to exfiltrate data after compromising OAuth tokens via device code phishing or other credential theft techniques. This rule detects both direct PowerShell access and PnP PowerShell module usage for file operations. FileAccessed events are included to detect adversaries reading file content via API and saving locally, bypassing traditional download methods. Normal users access SharePoint/OneDrive via browsers or sync clients, making PowerShell-based file access inherently suspicious.
Read More