OneDrive Malware File Upload | Elastic Security [8.19] | Elastic

OneDrive Malware File Upload

edit

IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

OneDrive Malware File Upload

Identifies the occurence of files uploaded to OneDrive being detected as Malware by the file scanning engine. Attackers can use File Sharing and Organization Repositories to spread laterally within the company and amplify their access. Users can inadvertently share these files without knowing their maliciousness, giving adversaries opportunity to gain initial access to other endpoints in the environment.

Rule type: query

Rule indices:

Severity: high

Risk score: 73

Runs every: 5m

Searches indices from: now-9m ( Date Math format, see also [Additional look-back time](/content/guide/en/security/8.19/rules-ui-create.html#rule-schedule "Set the rule’s schedule"/index.html))

Maximum alerts per execution: 100

References:

Tags:

Version: 210

Rule authors:

Rule license: Elastic License v2

Investigation guide

Triage and analysis

Disclaimer: This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs.

Investigating OneDrive Malware File Upload

OneDrive, a cloud storage service, facilitates file sharing and collaboration within organizations. However, adversaries can exploit this by uploading malware, which can spread across shared environments, leading to lateral movement within a network. The detection rule identifies such threats by monitoring OneDrive activities for malware detection events, focusing on file operations flagged by Microsoft’s security engine. This proactive approach helps in identifying and mitigating potential breaches.

Possible investigation steps

False positive analysis

Response and remediation

Setup

The Office 365 Logs Fleet integration, Filebeat module, or similarly structured data is required to be compatible with this rule.

Rule query

event.dataset:o365.audit and event.provider:OneDrive and event.code:SharePointFileOperation and event.action:FileMalwareDetected

Framework: MITRE ATT&CKTM

« O365 Email Reported by User as Malware or PhishSharePoint Malware File Upload »

On this page

Most Popular

Video

Get Started with Elasticsearch

Video

Intro to Kibana

Video

ELK for Logs & Metrics

Was this helpful?Feedback

LikeDislike

Thank you for your feedback.

a18132920325.cdn.optimizely.com

a18132920325.cdn.optimizely.com is blocked

This page has been blocked by an extension

ERR_BLOCKED_BY_CLIENT

Reload

This page has been blocked by an extension