For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon increase in Azure Microsoft Graph API request sizes

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

5 Days

Required Data

Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs

Detection Modules

Cloud

Detector Tags

Microsoft Graph Activity Logs

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Exfiltration Over Alternative Protocol (T1048)

Severity

Informational

Description

An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes.

Attacker's Goals

Exfiltrate data over Microsoft Graph API.

Investigative actions

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

Variations

Unusual Azure high-volume data transfer

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Exfiltration Over Alternative Protocol (T1048)

Severity

Medium

Description

An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes.

Attacker's Goals

Exfiltrate data over Microsoft Graph API.

Investigative actions

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

Suspicious Azure data transfer by identity

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Exfiltration Over Alternative Protocol (T1048)

Severity

Medium

Description

An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes.

Attacker's Goals

Exfiltrate data over Microsoft Graph API.

Investigative actions

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

Unusual data transfer from multiple Azure tenants

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Exfiltration Over Alternative Protocol (T1048)

Severity

Low

Description

An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes.

Attacker's Goals

Exfiltrate data over Microsoft Graph API.

Investigative actions

Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

Was this helpful?