From 2f99dd11212fe4b8cb6ea5274dfd58ce4ec75795 Mon Sep 17 00:00:00 2001 From: Steven Dick <38897662+nterl0k@users.noreply.github.com> Date: Tue, 28 Jan 2025 16:03:10 -0500 Subject: [PATCH] Update o365_exfiltration_via_file_download.yml --- detections/cloud/o365_exfiltration_via_file_download.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/cloud/o365_exfiltration_via_file_download.yml b/detections/cloud/o365_exfiltration_via_file_download.yml index c20775daf4..0bcffe5be7 100644 --- a/detections/cloud/o365_exfiltration_via_file_download.yml +++ b/detections/cloud/o365_exfiltration_via_file_download.yml @@ -39,7 +39,7 @@ tags: analytic_story: - Data Exfiltration - Office 365 Account Takeover - asset_type: Cloud + asset_type: O365 Tenant confidence: 50 impact: 50 message: The user $user$ downloaded an excessive number of files [$count$] from $file_path$ using $src$