Microsoft 365 File Retrieval May Appear as “FileAccessed,” Not “FileDownloaded”

Summary
Controlled testing found that file content retrieved from Microsoft 365 can generate a “FileAccessed” audit event without “FileDownloaded.” Investigators should assess access methods and surrounding evidence before ruling out acquisition.
Key points
- LevelBlue’s controlled testing successfully retrieved Microsoft 365 file content while the Unified Audit Log recorded “FileAccessed” rather than “FileDownloaded.”
- The article describes phishing and vishing-led account access followed by automated file exfiltration as a current threat pattern.
- Programmatic access through Microsoft Graph, APIs, scripts, or non-standard user agents may not produce the expected “FileDownloaded” event.
- Investigators should consider access method, user agent, activity volume and speed, authentication context, source infrastructure, and surrounding threat activity.
- “FileAccessed” alone neither proves nor rules out file acquisition; “FilePreviewed” also requires context and does not establish that the complete file was obtained.
Article Details
- Defense Focus
- Assess potential file acquisition during unauthorized Microsoft 365 access without relying exclusively on FileDownloaded audit events.
- Detection Methods
- Review FileAccessed events associated with Microsoft Graph, other APIs, and scripted or non-standard user agents.
- Identify high-volume, rapid sequential file access, especially access to numerous files within seconds or minutes and patterns inconsistent with normal interactive behavior.
- Correlate file access with preceding file enumeration, search, or reconnaissance.
- Correlate file events with suspicious source IP addresses, authentication context, and confirmed or suspected periods of unauthorized account access.
- Evaluate FilePreviewed separately: thumbnail rendering and browser prefetch can generate preview events without acquisition of the complete file.
- Data Sources
- Microsoft 365 Unified Audit Log events, including FileAccessed, FileDownloaded, and FilePreviewed
- User agent strings and access-method evidence
- File-access volume, timing, and sequence
- Authentication context and evidence of unauthorized account access
- Source IP addresses and surrounding threat activity
- Digital forensic artifacts relevant to file retrieval
- Defensive Actions
- Do not treat the absence of FileDownloaded events as evidence that file acquisition did not occur.
- Assess FileAccessed activity during unauthorized access using access method, user agent, volume, velocity, authentication context, and surrounding threat activity.
- Treat scripted or programmatic FileAccessed patterns as potential file acquisition when supported by the surrounding evidence.
- Do not treat FileAccessed or FilePreviewed alone as proof that complete files were acquired.
- Account for logging limitations and the totality of forensic evidence when making data-exposure assessments.
MITRE ATT&CK
T1078.004 · Cloud AccountsThreat actors abuse access to compromised M365 accounts and SSO-connected applications to retrieve additional data.T1530 · Data from Cloud StorageThreat actors programmatically retrieve SharePoint and OneDrive file content through Microsoft Graph and other APIs; successful retrieval may produce FileAccessed rather than FileDownloaded audit events.T1566 · PhishingThe article reports that threat actor groups use phishing to gain access to M365 email accounts.T1566.004 · Spearphishing VoiceThe article reports vishing used by threat actor groups to gain access to M365 email accounts.
Threat Actors
HelixNamed as an example of a threat actor group using phishing and vishing to gain M365 account access, followed by identity and token abuse for large-scale file exfiltration and extortion.PEARNamed as an example of a threat actor group using phishing and vishing to gain M365 account access, followed by identity and token abuse for large-scale file exfiltration and extortion.ShinyHuntersNamed as an example of a threat actor group using phishing and vishing to gain M365 account access, followed by identity and token abuse for large-scale file exfiltration and extortion.
Vendors
Products
JiraVariations of this playbook have also included leveraging SSO-connected access to third-party platforms (e.g., Salesforce, Jira, etc.) to exfiltrate additional data.Microsoft 365Threat actors may also leverage the My Apps page within Microsoft 365, which provides a centralized view of applications available to the user and is frequently used by threat actors to access connected services andMicrosoft Entra IDautomated large-scale file exfiltration and extortion campaigns targeting SharePoint, OneDrive, Microsoft Entra ID (formerly Azure AD), and email data through abuse of the Microsoft Graph API.Microsoft SharePointabuse, these actors have then automated large-scale file exfiltration and extortion campaigns targeting SharePoint, OneDrive, Microsoft Entra ID (formerly Azure AD), and email data through abuse of the Microsoft GraphOneDriveactors have then automated large-scale file exfiltration and extortion campaigns targeting SharePoint, OneDrive, Microsoft Entra ID (formerly Azure AD), and email data through abuse of the Microsoft Graph API.SalesforceVariations of this playbook have also included leveraging SSO-connected access to third-party platforms (e.g., Salesforce, Jira, etc.) to exfiltrate additional data.