Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a suspected data exfiltration incident. They have identified that a user account, 'UserA', downloaded a large number of files from a sanctioned cloud storage application (e.g., SharePoint Online) shortly before leaving the company. The analyst needs to find specific details about these download activities, including file names, sizes, and the exact timestamps of the downloads. Which Advanced Hunting table is most appropriate for querying this information in Microsoft Defender XDR?
- AEmailEvents
- BCloudAppEvents
- CIdentityLogonEvents
- DDeviceFileEvents
Show answer & explanationAnswer & explanation
Correct answer: B. CloudAppEvents
The CloudAppEvents table in Advanced Hunting captures activities related to cloud applications, including file downloads, uploads, and other interactions within sanctioned and unsanctioned cloud services. This table would provide the specific details about file downloads from SharePoint Online, including file names, sizes, and timestamps.
Why the other options are wrong
- A. EmailEvents tracks email-related activities, not file downloads from cloud storage.
- C. IdentityLogonEvents tracks user logon activities, not file download actions from cloud apps.
- D. DeviceFileEvents tracks file activities on endpoints, not directly from cloud applications like SharePoint Online.
Advanced Hunting: CloudAppEvents
An Advanced Hunting table in Microsoft Defender XDR that contains information about activities performed in sanctioned and unsanctioned cloud applications, including file operations, logins, and administrative actions.
- Crucial for investigating cloud-related incidents and data exfiltration.
- Provides details like user, app, activity type, IP address, and file properties.
- Integrates data from Microsoft Defender for Cloud Apps.
Memory trick: Cloud App Events show cloud activities.