Data from Information Repositories: Sharepoint T1213.002

Tactic: Collection

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (17 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
data_stream.dataset3eq 3o365.audit, azure.signinlogs
event.outcome3eq 3success
EventType2eq 1, in 1SearchQueryPerformed, fileaccessed, filedownloaded
Provider_Name2eq 1, in 1SharePoint, onedrive, sharepoint
EventData1contains 1search
Operation1eq 1searchqueryinitiatedsharepoint, searchqueryperformed
SearchQueryText1eq 1*
Workload1eq 1sharepoint
aws::userAgent1contains 1pnpcoresdk, pnpps, powershell
azure.signinlogs.properties.tenant_id1is_not_null 1
azure_ad::app_id1is_not_null 1
azure_ad::resource_id1in 100000003-0000-0ff1-ce00-000000000000, 6a9b9266-8161-4a7b-913a-a9eda19da220
command1ne 1(*), *
count1gt 120
o365.audit.SearchQueryText1contains 1, is_not_null 1, ne 11099, access key, account number

Top indicator values (105 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
3375
data_stream.dataseteq
o365.audit
247
data_stream.dataseteq
azure.signinlogs
136
EventDatacontains
search
1
EventTypeeq
SearchQueryPerformed
1
EventTypein
fileaccessed
1
EventTypein
filedownloaded
1
Operationeq
searchqueryinitiatedsharepoint
1
Operationeq
searchqueryperformed
1
Provider_Nameeq
SharePoint
1
Provider_Namein
onedrive
13
Provider_Namein
sharepoint
13
SearchQueryTexteq
*
1
Workloadeq
sharepoint
12
aws::userAgentcontains
pnpcoresdk
1
aws::userAgentcontains
pnpps
1
aws::userAgentcontains
powershell
1
aws::userAgentcontains
sharepointpnp
1
azure_ad::resource_idin
00000003-0000-0ff1-ce00-000000000000
12
azure_ad::resource_idin
6a9b9266-8161-4a7b-913a-a9eda19da220
1
commandne
(*)
12
commandne
*
12
countgt
20
16
o365.audit.SearchQueryTextcontains
1099
1
o365.audit.SearchQueryTextcontains
access key
1
o365.audit.SearchQueryTextcontains
account number
1
o365.audit.SearchQueryTextcontains
acquisition
1
o365.audit.SearchQueryTextcontains
admin
1
o365.audit.SearchQueryTextcontains
api key
1
o365.audit.SearchQueryTextcontains
apikey
1

Exclusions (9 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
azure.signinlogs.properties.app_owner_tenant_ideq
f8cdef31-a31e-4b4a-93e4-5f571e91255a
1
azure_ad::app_idin
00000003-0000-0ff1-ce00-000000000000
1
azure_ad::app_idin
08e18876-6177-487e-b8b5-cf950c1e598c
1
azure_ad::app_idin
5e3ce6c0-2b1f-4285-8d4b-75ee78787346
1
azure_ad::app_idin
9199bf20-a13f-4107-85dc-02114787ef48
1
azure_ad::app_idin
ab9b8c07-8f02-4f72-87fa-80105867a763
1
azure_ad::app_idin
af124e86-4e96-495a-b70a-90f90ab96707
1
azure_ad::app_idin
cc15fd57-2c6c-4117-a88c-83b1d56b4bbe
1
azure_ad::signin_categoryeq
microsoftserviceprincipalsigninlogs
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 3 rules

Splunk 1 rule