{"id":"18b88d08-d73e-4f21-bc25-4b9892a4fdd0","title":"PST Export Alert Using eDiscovery Alert","description":"Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content","author":"Sorina Ionescu","status":"test","level":"medium","date":"2022-02-08","modified":"2022-11-17","tags":["attack.collection","attack.t1114"],"technique_ids":["T1114"],"logsource":{"service":"threat_management","product":"m365","definition":"Requires the 'eDiscovery search or exported' alert to be enabled"},"falsepositives":["PST export can be done for legitimate purposes but due to the sensitive nature of its content it must be monitored."],"references":["https://learn.microsoft.com/en-us/microsoft-365/compliance/alert-policies?view=o365-worldwide"],"source_path":"rules/cloud/m365/threat_management/microsoft365_pst_export_alert.yml","source_sha256":"cd3e91f5ed123645ba2a0a3c47b54c7c07608d00a556e3727813f15aca392298","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/m365/threat_management/microsoft365_pst_export_alert.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: PST Export Alert Using eDiscovery Alert\nid: 18b88d08-d73e-4f21-bc25-4b9892a4fdd0\nrelated:\n    - id: 6897cd82-6664-11ed-9022-0242ac120002\n      type: similar\nstatus: test\ndescription: Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content\nreferences:\n    - https://learn.microsoft.com/en-us/microsoft-365/compliance/alert-policies?view=o365-worldwide\nauthor: Sorina Ionescu\ndate: 2022-02-08\nmodified: 2022-11-17\ntags:\n    - attack.collection\n    - attack.t1114\nlogsource:\n    service: threat_management\n    product: m365\n    definition: Requires the 'eDiscovery search or exported' alert to be enabled\ndetection:\n    selection:\n        eventSource: SecurityComplianceCenter\n        eventName: 'eDiscovery search started or exported'\n        status: success\n    condition: selection\nfalsepositives:\n    - PST export can be done for legitimate purposes but due to the sensitive nature of its content it must be monitored.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1114","id":"T1114","name":"Email Collection","page":"techniques/enterprise/T1114/"}],"data_path":"data/detection-rules/18b88d08-d73e-4f21-bc25-4b9892a4fdd0.json","kind":"sigma"}
