kevmap

TechniquesT1567.004 › AN0440

AN0440 Analytic 0440

SaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Suspicious SaaS tenant activity involving webhook configurations pointing to external or untrusted domains. Defender perspective: repeated automated exports or suspicious webhook endpoint registrations.</p>
Detects
T1567.004 Exfiltration Over Webhook
Part of
DET0153 Detection Strategy for Exfiltration Over Webhook

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedSet-Mailbox, Add-InboxRule, RegisterWebhookDC0038 Application Log Content
saas:apiWebhook registrations or repeated POST activityDC0078 Network Traffic Flow

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
WebhookRegistrationsMonitor new webhook creation events in SaaS environments.
ExternalDomainsFlag webhooks pointing to domains not owned by the enterprise.