Skip to content

Sharepoint Rules

2 detection rules in this category.

RuleSeverityMITRESource
Anonymous link createdHighT1567AuditLog
File malware detectedCriticalT1204.002AuditLog

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1567 (Exfiltration)

Anonymous sharing link created - data exposure risk

Conditions
  • Match: all
  • Operation Equals AnonymousLinkCreated

File malware detected

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1204.002 (Execution)

Malware detected in uploaded file

Conditions
  • Match: all
  • Operation Equals FileMalwareDetected