2026 Critical Enterprise Intrusion Chain Detection: Mass File Download or Sync from SharePoint/OneDrive Following Account Takeover Indicators
This rule detects potentially compromised accounts by correlating suspicious authentication activity (such as risky sign-ins, impossible travel, or malicious OAuth/Mail-rule configurations) with a subsequent spike in SharePoint or OneDrive file access, downloads, or external link sharing within a one-hour window. This behavior is indicative of an adversary performing cloud-based data exfiltration after gaining unauthorized access to an account.
CQL

