Microsoft Sentinel medium experimental kql
Netskope - Heavy Personal Cloud Storage Usage (Shadow IT)
Detects heavy usage of personal cloud storage applications like personal Dropbox, Google Drive, OneDrive personal, etc. Indicates potential Shadow IT or data leakage risk.
Detection Logic
let heavyUsageThresholdMB = 500;
NetskopeWebTransactions_CL
| where TimeGenerated > ago(1h)
| where isnotempty(CsUsername) and isnotempty(XCsApp)
| where XCsApp has_any ('Dropbox', 'Google Drive', 'OneDrive', 'Box', 'iCloud', 'pCloud', 'MEGA', 'MediaFire', 'WeTransfer')
| where XCsAppInstanceTag contains 'Personal'
or XCsAppInstanceName contains 'Personal'
or XCsAppTags contains 'Unsanctioned'
or not(XCsAppTags contains 'Enterprise')
| summarize
TotalBytes = sum(Bytes),
UploadBytes = sum(CsBytes),
DownloadBytes = sum(ScBytes),
FileCount = dcount(XCsAppObjectName),
Files = make_set(XCsAppObjectName, 10),
Activities = make_set(XCsAppActivity),
EventCount = count()
by CsUsername, XCsApp, XCsAppCategory, XCsAppInstanceName, XCsAppTags, XCDevice, XCCountry
| extend
TotalMB = round(TotalBytes / 1048576.0, 2),
UploadMB = round(UploadBytes / 1048576.0, 2),
DownloadMB = round(DownloadBytes / 1048576.0, 2)
| where TotalMB > heavyUsageThresholdMB or FileCount > 50
| project
TimeGenerated = now(),
User = CsUsername,
CloudApplication = XCsApp,
AppCategory = XCsAppCategory,
AppInstance = XCsAppInstanceName,
AppTags = XCsAppTags,
TotalDataMB = TotalMB,
UploadMB,
DownloadMB,
FileCount,
Files,
Activities,
Device = XCDevice,
Country = XCCountry,
EventCount Field Validations
Loading…
Comments (0)
Loading comments...