o365_onedrive_anonymous_file_accessed
Description
Anonymous links can be used to export files from OneDrive. While this isn't always a sign of malicious activity, some organizations do not support the use of anonymous links because of the risk of data leakage. This rule detects when anonymous links are used to access files from OneDrive.
Query · yara_l
events:
$file.metadata.event_type = "USER_RESOURCE_ACCESS"
$file.metadata.product_event_type = "FileAccessed"
$file.metadata.product_name = "Office 365"
$file.metadata.vendor_name = "Microsoft"
(
$file.principal.user.userid = /^urn:spo:anon#/ or
$file.principal.user.userid = "anonymous"
)
$file.principal.ip = $ip
match:
$ip over 5m
outcome:
$risk_score = 35
$event_count = count_distinct($file.metadata.id)
$referral_url = array_distinct($file.network.http.referral_url)
$user_agent = array_distinct($file.network.http.user_agent)
$principal_application = array_distinct($file.principal.application)
$principal_ip = array_distinct($file.principal.ip) //IP is a Microsoft IP address not the individual who accessed the file
$target_application = array_distinct($file.target.application)
$principal_user_userid = array_distinct($file.principal.user.userid)
$target_file_full_path = array_distinct($file.target.file.full_path)
$target_url = array_distinct($file.target.url)
condition:
$file