SharePointFileOperation via previously unseen IPs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Shows SharePoint upload/download volume by IPs with high-risk ASNs. New IPs with volume spikes may be unauthorized and exfiltrating documents.

Attribute Value
Type Hunting Query
Solution Microsoft 365
ID e3d24cfd-b2a1-4ba7-8f80-0360892f9d57
Tactics Exfiltration
Techniques T1030
Required Connectors AzureActiveDirectory, Office365
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
OfficeActivity RecordType == "SharePointFileOperation" ?
SigninLogs ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Microsoft 365