File tree Expand file tree Collapse file tree 1 file changed +9
-20
lines changed Expand file tree Collapse file tree 1 file changed +9
-20
lines changed Original file line number Diff line number Diff line change @@ -36,38 +36,27 @@ drilldown_searches:
36
36
search : ' `o365_management_activity` Operation IN ("filesyncdownload*") UserId="$UserId$"'
37
37
earliest_offset : $info_min_time$
38
38
latest_offset : $info_max_time$
39
+ rba :
40
+ message : The user $user$ synced an excessive number of files [$count$] from $file_path$ using $src$
41
+ risk_objects :
42
+ - field : user
43
+ type : user
44
+ score : 25
45
+ threat_objects :
46
+ - field : src
47
+ type : src
39
48
tags :
40
49
analytic_story :
41
50
- Data Exfiltration
42
51
- Office 365 Account Takeover
43
52
asset_type : O365 Tenant
44
- confidence : 50
45
- impact : 50
46
- message : The user $user$ synced an excessive number of files [$count$] from $file_path$ using $src$
47
53
mitre_attack_id :
48
54
- T1567
49
55
- T1530
50
- observable :
51
- - name : user
52
- type : User
53
- role :
54
- - Victim
55
- - name : src
56
- type : IP Address
57
- role :
58
- - Attacker
59
56
product :
60
57
- Splunk Enterprise
61
58
- Splunk Enterprise Security
62
59
- Splunk Cloud
63
- required_fields :
64
- - _time
65
- - Operation
66
- - UserAgent
67
- - Workload
68
- - UserId
69
- - SiteUrl
70
- risk_score : 25
71
60
security_domain : threat
72
61
tests :
73
62
- name : True Positive Test
You can’t perform that action at this time.
0 commit comments