Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a suspected data exfiltration incident. They have identified that a user account was used to download a large number of files from an internal SharePoint Online site, which is monitored by Microsoft Defender for Cloud Apps. The analyst needs to determine the exact files downloaded, the time of download, and the size of each file. Which KQL table in Advanced Hunting should the analyst query to retrieve this specific information?
- AIdentityLogonEvents
- BCloudAppEvents
- CEmailAttachmentInfo
- DDeviceFileEvents
Show answer & explanationAnswer & explanation
Correct answer: B. CloudAppEvents
CloudAppEvents captures activities within cloud applications like SharePoint Online, including file-related actions such as downloads, along with details like the file name, size, and timestamp of the event. This makes it the most suitable table for this investigation.
Why the other options are wrong
- A. IdentityLogonEvents records user login activities, not file download details from cloud applications.
- C. EmailAttachmentInfo provides details about email attachments, not files downloaded from SharePoint Online.
- D. DeviceFileEvents tracks file activities on *endpoints*, not directly within cloud services like SharePoint Online.
KQL: CloudAppEvents (File Downloads)
The Advanced Hunting table in Microsoft Defender XDR that provides detailed logs of activities occurring within cloud applications, including specific events related to files such as downloads, uploads, and access.
- Records activities in cloud apps (e.g., SharePoint, OneDrive).
- Includes file-specific details (name, size, hash).
- Crucial for investigating data exfiltration from cloud services.
Memory trick: For file actions in 'cloud apps', check 'CloudAppEvents'.