Anomalous M365 Sharepoint File Transfer Activity
Last updated on:
Applies to: Log360Log360 Cloud
In this page
About the rule
Rule Type
Anomaly
Rule Description
Detects anomalous file transfer activity in SharePoint or OneDrive, including transfers at unusual times or with abnormal volume by a user.
Severity
Trouble
Rule Requirement
Criteria
Action1:
actionname = "SharePoint File Transfer"
| isanomalous(User at an unusual Time)
| isanomalous(User with abnormal Count)
| isanomalous(User with unusual IP Address)
select Action1.TARGET_NAME,Action1.RESOURCE,Action1.FILETYPE,Action1.TARGET,Action1.IPADDRESS,Action1.SIZE_I,Action1.USERAGENT,Action1.CALLER,Action1.OPERATION
Detection
Execution Mode
Intelligent
Log Sources
Microsoft 365


