Dataverse - Dataverse export copied to USB devices

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query uses XDR data from M365 Defender to detect files downloaded from a Dataverse instance and copied to USB drive.

Attribute Value
Type Hunting Query
Solution Microsoft Business Applications
ID f9658e11-e277-4a65-8f91-2cb94cf7497c
Tactics Exfiltration
Techniques T1052, T1052.001
Required Connectors Dataverse, MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DataverseActivity ?
DeviceEvents ?
DeviceInfo ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Microsoft Business Applications