User accessed multiple O365 AIP sensitive files
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
O365 DLP Analytics
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data from Information Repositories (T1213), Data from Local System (T1005)
Severity
Informational
Description
A user accessed multiple O365 AIP sensitive files.
Attacker's Goals
An attacker is attempting to collect sensitive information.
Investigative actions
Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Follow further actions done by the account.
Check what sensitivity labels are detected and how suspicious they are.
Examine the user's account history for suspicious behavior.
Was this helpful?
