Title:PST Export Alert Using eDiscovery Alert Status:test Description:Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content References: -https://learn.microsoft.com/en-us/microsoft-365/compliance/alert-policies?view=o365-worldwide Author: Sorina Ionescu Date: 2022-02-08 modified:2022-11-17 Tags:
-'attack.collection'
-'attack.t1114'
Logsource:
service: threat_management
product: m365
definition: Requires the 'eDiscovery search or exported' alert to be enabled
Detection: selection: eventSource:
'SecurityComplianceCenter' eventName:
'eDiscovery search started or exported' status:
'success' condition:selection Falsepositives:
-PST export can be done for legitimate purposes but due to the sensitive nature of its content it must be monitored. Level:medium