mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update o365_exfiltration_via_file_download.yml
This commit is contained in:
@@ -39,7 +39,7 @@ tags:
|
||||
analytic_story:
|
||||
- Data Exfiltration
|
||||
- Office 365 Account Takeover
|
||||
asset_type: Cloud
|
||||
asset_type: O365 Tenant
|
||||
confidence: 50
|
||||
impact: 50
|
||||
message: The user $user$ downloaded an excessive number of files [$count$] from $file_path$ using $src$
|
||||
|
||||
Reference in New Issue
Block a user