SharePointFileOperation via clientIP with previously unseen user agents

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


New user agents associated with a clientIP for SharePoint file uploads/downloads.

Attribute Value
Type Hunting Query
Solution Microsoft 365
ID e8ae1375-4640-430c-ae8e-2514d09c71eb
Tactics Exfiltration
Techniques T1030
Required Connectors Office365
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
OfficeActivity RecordType == "SharePointFileOperation" ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Microsoft 365