Rare DLP rule match by user
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection, Email
Detector Tags
O365 DLP Analytics
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data from Information Repositories: Sharepoint (T1213.002), Data from Information Repositories (T1213)
Severity
Informational
Description
A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information.
Attacker's Goals
An attacker is attempting to access sensitive information.
Investigative actions
Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity).
Follow further actions done by the account.
Communicate with the user to verify the legitimacy of the triggered event.
Variations
Was this helpful?
