Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
10 Minutes |
Deduplication Period |
5 Days |
Required Data |
|
Detection Modules |
Cloud |
Detector Tags |
Microsoft Graph Activity Logs |
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
An Identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes.
Attacker's Goals
Exfiltrate data over Microsoft Graph API.
Investigative actions
Check the identity's role designation in the organization.
Check if there are additional calls executed by the identity.
Variations
Unusual Azure high-volume data transferSuspicious Azure data transfer by identity
Unusual data transfer from multiple Azure tenants