heroui logo

O365 PST export alert

Splunk Security Content

View Source
Summary
The O365 PST Export Alert analytic is designed to monitor and identify potentially malicious activities associated with the export of PST files, particularly within Office 365 environments. It analyzes Office 365 management activity logs to detect when a user initiates an eDiscovery search or exports a PST file, specifically filtering for events categorized under ThreatManagement with the designation "eDiscovery search started or exported." This activity can signal possible data exfiltration attempts or unauthorized access to sensitive information, necessitating immediate investigation to confirm or refute any malicious intent. The analytic highlights the risk of data breaches, loss of intellectual property, and unauthorized access to critical communications, making it imperative for organizations to maintain vigilance over user activities related to data export processes.
Categories
  • Cloud
  • Application
Data Sources
  • Cloud Service
  • Application Log
ATT&CK Techniques
  • T1114
Created: 2024-11-14