1200KM / sigma-rule
Data Exfiltration to Unsanctioned Apps — Sigma Rule
Sigma rule 2b669496-d215-47d8-bd9a-f4a45bf07cda. Data Exfiltration to Unsanctioned Apps — Sigma Rule. Detects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform an activity that resembles an attempt to exfiltrate information from your organization.
Rule metadata and linked tags
Author: Austin Songer @austinsonger. Source status: test; severity: medium. Source dates: 2021-08-23 / 2022-10-09.
{
"service": "threat_management",
"product": "m365"
}Pinned original Sigma rule · Detection Rule License 1.1
Source SHA-256: 2192f79aee03d4e4e84da2a1fe67a38777d04e2759ea91621ceeaece1b44d285
Detection logic
Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.
title: Data Exfiltration to Unsanctioned Apps
id: 2b669496-d215-47d8-bd9a-f4a45bf07cda
status: test
description: Detects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform an activity that resembles an attempt to exfiltrate information from your organization.
references:
- https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy
- https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference
author: Austin Songer @austinsonger
date: 2021-08-23
modified: 2022-10-09
tags:
- attack.exfiltration
- attack.t1537
logsource:
service: threat_management
product: m365
detection:
selection:
eventSource: SecurityComplianceCenter
eventName: 'Data exfiltration to unsanctioned apps'
status: success
condition: selection
falsepositives:
- Unknown
level: medium
False positives
- Unknown
Source references
Connected ecosystem references
Exact source-tagged techniques
Telemetry review
Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.