User accessed SaaS resource via anonymous link
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Google Workspace Audit Logs OR Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data from Cloud Storage (T1530)
Severity
Informational
Description
A user accessed a SaaS resource via an anonymous link.
Attacker's Goals
An attacker is attempting to collect sensitive data.
Investigative actions
Check the IP address from which the access originated.
Examine the file that was accessed for any sensitive indicators.
Follow further actions taken, such as downloading files.
Variations
Was this helpful?
