Insider Threat: Top 3 Indicators of Data Exfiltration in Cloud Applications
ID: 0400f468-e12d-5140-a1b7-1df504840973
STIX ID: report--0400f468-e12d-5140-a1b7-1df504840973
Feed Name: ReliaQuest Blog
Threat Score
This document provides guidance for detecting insider data exfiltration from SharePoint, highlighting useful indicators such as unusual user-agent strings, unexpected geolocation for file downloads, and ISPs linked to VPN services; it also recommends using ReliaQuest GreyMatter to aggregate and enrich telemetry for investigation and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
