PST Export Alert Using New-ComplianceSearchAction

 Original Source: [Sigma source]
Title: PST Export Alert Using New-ComplianceSearchAction
Status: test
Description:Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.
References:
  -https://learn.microsoft.com/en-us/powershell/module/exchange/new-compliancesearchaction?view=exchange-ps
Author: Nikita Khalimonenkov
Date: 2022-11-17
modified:None
Tags:
  • -'attack.collection'
  • -'attack.t1114'
Logsource:
  • service: threat_management
  • product: m365
Detection:
  selection:
    eventSource: 'SecurityComplianceCenter'
    Payload|contains|all:
      -'New-ComplianceSearchAction'
      -'Export'
      -'pst'

  condition:selection
Falsepositives:
  -Exporting a PST can be done for legitimate purposes by legitimate sources, but due to the sensitive nature of PST content, it must be monitored.
Level: medium