Skip to content

eDiscovery Rules

1 detection rule in this category.

RuleSeverityMITRESource
eDiscovery search exportedCriticalT1213.002AuditLog

eDiscovery search exported

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1213.002 (Collection)

eDiscovery search results exported - potential data exfiltration

Conditions
  • Match: all
  • Operation Equals New-ComplianceSearchAction
  • Parameters.Action Equals Export