LoFP LoFP / t1213

t1213

TitleTags
a self-hosted runner is automatically removed from github if it has not connected to github actions for more than 14 days.
allowed self-hosted runners changes in the environment.
an ephemeral self-hosted runner is automatically removed from github if it has not connected to github actions for more than 1 day.
developers testing new applications or oauth flows in non-production tenants may generate alerts during development cycles.
hr or finance personnel legitimately searching for employee or financial records.
it administrators searching for configuration or infrastructure documentation.
it administrators using pnp powershell for site management, migration, or backup operations.
legal teams searching for contract or privileged documents.
legitimate automation scripts using powershell to interact with sharepoint or onedrive for business purposes.
legitimate user activity.
new legitimate applications or integrations recently deployed in the environment may trigger this detection during initial setup or rollout phases.
security or compliance teams using ediscovery or content search for legitimate investigations.
snapshot exports may be performed by administrators, automation pipelines, or data engineering workflows. confirm whether the export was expected and initiated by an authorized user, role, or automation process. snapshot exports by unfamiliar principals or from unexpected networks should be investigated. if known behavior causes false positives, it can be exempted from the rule.
third-party saas applications with sharepoint integration may appear as new app ids when users first authorize access.
unlikely
validate the actor if permitted to access the repo.
validate the deletion activity is permitted. the \"actor\" field need to be validated.
validate the multifactor authentication changes.