Title:
PST Export Alert Using New-ComplianceSearchAction
Status:
test
Description:Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.
References:
-https://learn.microsoft.com/en-us/powershell/module/exchange/new-compliancesearchaction?view=exchange-ps
Author: Nikita Khalimonenkov
Date: 2022-11-17
modified:None
Tags:
- -'attack.collection'
- -'attack.t1114'
Logsource:
- service: threat_management
- product: m365
Detection:
selection:
eventSource:
'SecurityComplianceCenter'
Payload|contains|all:
-'New-ComplianceSearchAction'
-'Export'
-'pst'
condition:
selection
Falsepositives:
-Exporting a PST can be done for legitimate purposes by legitimate sources, but due to the sensitive nature of PST content, it must be monitored.
Level:
medium