kevmap

Log sources › m365:sharepoint

m365:sharepoint

Inverted view: what can be detected if this is the log you have. Office Suite, Windows

4
channels
4
analytics
4
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
AnonymousLinkCreated, FileDownloaded DC0025 Cloud Storage Access AN1330 1
Enumerate ACLs/role bindings DC0105 Group Metadata AN0696 1
File access with forged or anomalous SAML claims DC0067 Logon Session Creation AN0422 1
Multiple file download operations on a site by a privileged account in a short time window DC0070 Cloud Service Metadata AN1380 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1069.003 Cloud Groupsdiscovery10
T1213.002 Sharepointcollection00
T1530 Data from Cloud Storagecollection02
T1606.002 SAML Tokenscredential access00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2023-22952SugarCRM Multiple Products T1530 Stale
CVE-2024-49035Microsoft Partner Center T1530 Mapped