A user uploaded malware to SharePoint or OneDrive
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
3 Hours
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Data Detection & Response
ATT&CK Tactic
Lateral Movement (TA0008), Execution (TA0002)
ATT&CK Technique
Taint Shared Content (T1080), User Execution: Malicious File (T1204.002)
Severity
Low
Description
A user uploaded a file that was classified as malware to SharePoint or OneDrive.
Attacker's Goals
An attacker may upload malware to a shared location to gain execution and move laterally.
Investigative actions
Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Check the file that was uploaded for any malicious indicators.
Follow further actions done by the account.
Variations
Was this helpful?
