{"id":"6897cd82-6664-11ed-9022-0242ac120002","title":"PST Export Alert Using New-ComplianceSearchAction","description":"Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.","author":"Nikita Khalimonenkov","status":"test","level":"medium","date":"2022-11-17","modified":"","tags":["attack.collection","attack.t1114"],"technique_ids":["T1114"],"logsource":{"service":"threat_management","product":"m365"},"falsepositives":["Exporting a PST can be done for legitimate purposes by legitimate sources, but due to the sensitive nature of PST content, it must be monitored."],"references":["https://learn.microsoft.com/en-us/powershell/module/exchange/new-compliancesearchaction?view=exchange-ps"],"source_path":"rules/cloud/m365/threat_management/microsoft365_pst_export_alert_using_new_compliancesearchaction.yml","source_sha256":"bde3905507db16348395c697ceb808ea8d7b5f2790390505836456227e6a7cb2","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/m365/threat_management/microsoft365_pst_export_alert_using_new_compliancesearchaction.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: PST Export Alert Using New-ComplianceSearchAction\nid: 6897cd82-6664-11ed-9022-0242ac120002\nrelated:\n    - id: 18b88d08-d73e-4f21-bc25-4b9892a4fdd0\n      type: similar\nstatus: test\ndescription: Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.\nreferences:\n    - https://learn.microsoft.com/en-us/powershell/module/exchange/new-compliancesearchaction?view=exchange-ps\nauthor: Nikita Khalimonenkov\ndate: 2022-11-17\ntags:\n    - attack.collection\n    - attack.t1114\nlogsource:\n    service: threat_management\n    product: m365\ndetection:\n    selection:\n        eventSource: SecurityComplianceCenter\n        Payload|contains|all:\n            - 'New-ComplianceSearchAction'\n            - 'Export'\n            - 'pst'\n    condition: selection\nfalsepositives:\n    - Exporting a PST can be done for legitimate purposes by legitimate sources, but due to the sensitive nature of PST content, it must be monitored.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1114","id":"T1114","name":"Email Collection","page":"techniques/enterprise/T1114/"}],"data_path":"data/detection-rules/6897cd82-6664-11ed-9022-0242ac120002.json","kind":"sigma"}
