Massive upload to SaaS service
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
3 Hours
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Box Audit Log OR DropBox OR Google Workspace Audit Logs OR Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010), Collection (TA0009)
ATT&CK Technique
Exfiltration Over Web Service (T1567), Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002), Data Staged: Remote Data Staging (T1074.002)
Severity
Informational
Description
A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged.
Attacker's Goals
An attacker may upload files to a SaaS service to stage and exfiltrate data from the organization.
Investigative actions
Check for signs of account compromise, such as abnormal login activity or unusual behavior.
Review the files that were uploaded to determine if they contain sensitive data.
Verify if the user account that uploaded the files is authorized to access them.
Analyze the file types that were uploaded.
Monitor the account for any further suspicious actions.
Variations
Was this helpful?
