kevmap

TechniquesT1537 › AN1582

AN1582 Analytic 1582

SaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.</p>
Detects
T1537 Transfer Data to Cloud Account
Part of
DET0573 Cross-Platform Detection of Data Transfer to Cloud Account

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
saas:googledrivedrive.permission.addDC0023 Cloud Storage Modification
saas:boxcollaboration.inviteDC0027 Cloud Storage Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
UserContextWhether the user is in a high-privileged or VIP group
DomainReputationListAllowlist or blocklist of external SaaS domains
PayloadVolumeThresholdSize or number of shared files triggering alert