kevmap

TechniquesT1213.002 › AN1380

AN1380 Analytic 1380

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Privileged or rarely used accounts performing bulk access to SharePoint files or metadata over a short time window, indicating potential scripted collection of sensitive internal documents.</p>
Detects
T1213.002 Sharepoint
Part of
DET0500 Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedFileAccessed, FileDownloaded, SearchQueriedDC0038 Application Log Content
azure:signinlogsUserLogin, ConditionalAccessPolicyEvaluatedDC0067 Logon Session Creation
m365:sharepointMultiple file download operations on a site by a privileged account in a short time windowDC0070 Cloud Service Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
UserContextCan be adjusted to focus on specific high-privilege or rarely-used service accounts
TimeWindowDefines the aggregation period for multiple download events (e.g., 10 minutes)
DownloadThresholdMinimum number of documents accessed/downloaded to trigger alert
SiteScopeLimit detection to sensitive SharePoint sites such as HR, Finance, Engineering