For the complete documentation index, see llms.txt. This page is also available as Markdown.

User accessed SaaS resource via anonymous link

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Google Workspace Audit Logs OR Office 365 Audit

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Data from Cloud Storage (T1530)

Severity

Informational

Description

A user accessed a SaaS resource via an anonymous link.

Attacker's Goals

An attacker is attempting to collect sensitive data.

Investigative actions

  • Check the IP address from which the access originated.

  • Examine the file that was accessed for any sensitive indicators.

  • Follow further actions taken, such as downloading files.

Variations

User accessed a public Google Drive document

Synopsis

Field
Value

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Data from Cloud Storage (T1530)

Severity

Informational

Description

A user accessed a Google Drive document that is public on the web.

Attacker's Goals

An attacker is attempting to collect sensitive data.

Investigative actions

  • Check the IP address from which the access originated.

  • Examine the file that was accessed for any sensitive indicators.

  • Follow further actions taken, such as downloading files.

Was this helpful?