Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
10 Minutes |
Deduplication Period |
5 Days |
Required Data |
|
Detection Modules |
Cloud |
Detector Tags |
Microsoft Graph Activity Logs |
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
An Identity performed multiple Microsoft Graph actions, resulting in a high volume of data transfer.
Attacker's Goals
Exfiltrate data over Microsoft Graph API.
Investigative actions
Check the identity's role designation in the organization.
Check if there are additional calls executed by the identity.
Variations
Unusual Azure high-volume data transferSuspicious Azure high-volume data transfer by identity
Unusual high-volume data transfer from multiple Azure tenants