o365_onedrive_anonymous_link_accessed


Description

Anonymous links can be used to access files from OneDrive. While this isn't always a sign of malicious activity, some organizations do not support the use of anonymous links because of the risk of data leakage. This rule detects when anonymous links are used to access files from OneDrive.

Query · yara_l

events:
    $file.metadata.event_type = "USER_RESOURCE_ACCESS"
    $file.metadata.product_event_type = "AnonymousLinkUsed"
    $file.metadata.product_name = "Office 365"
    $file.metadata.vendor_name = "Microsoft"
    $file.principal.user.userid = "anonymous"
    $file.principal.ip = $ip

  match:
    $ip over 5m

  outcome:
    $risk_score = 35
    $event_count = count_distinct($file.metadata.id)
    $referral_url = array_distinct($file.network.http.referral_url)
    $user_agent = array_distinct($file.network.http.user_agent)
    $principal_application = array_distinct($file.principal.application)
    $principal_ip = array_distinct($file.principal.ip)
    $target_application = array_distinct($file.target.application)
    $principal_user_userid = array_distinct($file.principal.user.userid)
    $target_file_full_path = array_distinct($file.target.file.full_path)
    $target_url = array_distinct($file.target.url)

  condition:
    $file
Raw source o365_onedrive_anonymous_link_accessed · YARA-L
Esc
Published by chronicle/detection-rules ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
rule o365_onedrive_anonymous_link_accessed {

  meta:
    author = "Google Cloud Security"
    description = "Anonymous links can be used to access files from OneDrive. While this isn't always a sign of malicious activity, some organizations do not support the use of anonymous links because of the risk of data leakage. This rule detects when anonymous links are used to access files from OneDrive."
    rule_id = "mr_7e67005a-d5fc-4497-8e81-e6797b2f54e9"
    rule_name = "O365 OneDrive Anonymous Link Accessed"
    tactic = "TA0010"
    technique = "T1048.002"
    type = "hunt"
    platform = "azure"
    data_source = "o365"
    severity = "Medium"
    priority = "Medium"

  events:
    $file.metadata.event_type = "USER_RESOURCE_ACCESS"
    $file.metadata.product_event_type = "AnonymousLinkUsed"
    $file.metadata.product_name = "Office 365"
    $file.metadata.vendor_name = "Microsoft"
    $file.principal.user.userid = "anonymous"
    $file.principal.ip = $ip

  match:
    $ip over 5m

  outcome:
    $risk_score = 35
    $event_count = count_distinct($file.metadata.id)
    $referral_url = array_distinct($file.network.http.referral_url)
    $user_agent = array_distinct($file.network.http.user_agent)
    $principal_application = array_distinct($file.principal.application)
    $principal_ip = array_distinct($file.principal.ip)
    $target_application = array_distinct($file.target.application)
    $principal_user_userid = array_distinct($file.principal.user.userid)
    $target_file_full_path = array_distinct($file.target.file.full_path)
    $target_url = array_distinct($file.target.url)

  condition:
    $file
}

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.