Skip to content

Commit 4ca537c

Browse files
authored
initial upload
1 parent 7afa788 commit 4ca537c

File tree

2 files changed

+15
-0
lines changed

2 files changed

+15
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:c0edf045b5e5ed56ce67dd3ecd98c2fbfe7b346f8926318c76f268cf87890a1e
3+
size 29506
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
author: Steven Dick
2+
id: 722e396e-9e74-4516-882d-0fc94f5d2b33
3+
date: '2024-12-19'
4+
description: 'Sample of events when Sharepoint is searched for a sensitive term / or high rate of searching.'
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1213.002/o365_sus_sharepoint_search/o365_sus_sharepoint_search.log
8+
sourcetypes:
9+
- o365:management:activity
10+
references:
11+
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
12+
- https://attack.mitre.org/techniques/T1213/002/

0 commit comments

Comments
 (0)