Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Burst of M365 Downloads Following Risky Sign-In (AiTM to SaaS Exfil)

Falcon Exfiltration Sentinel
MITRE ATT&CK
Data from Cloud Storage
Data Source
CloudAppEvents
Date Added
2026-09-18
Last Updated
2026-09-18
Source
Google Cloud Blog, Mallory (mallory.ai/stories/019fd844-a778-7695-8f7d-201696b7d530)
What This Detects
After AiTM credential/session theft, UNC6671/Falcon runs automated scripts to bulk-exfiltrate data from SaaS apps (Microsoft 365, Okta). ~$10.69M collected across the UNC6671 brand family; targets financial services, private equity, legal, healthcare, manufacturing.
Query
CloudAppEvents
| where ActionType in ("FileDownloaded","FileSyncDownloadedFull","FileExported")
| summarize DownloadCount = count() by AccountId, IPAddress, bin(Timestamp, 15m)
| where DownloadCount > 50

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.