2026 Critical Enterprise Intrusion Chain Detection: Bulk Cloud Storage Download by Recently Flagged Risky Identity
Detects high-volume file download activity in Office 365/SharePoint/OneDrive audit logs. The rule correlates download spikes with users who have recently triggered security alerts related to session hijacking, token theft, or risky sign-ins, which are indicators of a potential cloud account takeover scenario.
Cortex XDR

