Microsoft 365 File Retrieval May Appear as “FileAccessed,” Not “FileDownloaded”

· Original article ↗

Summary

Controlled testing found that file content retrieved from Microsoft 365 can generate a “FileAccessed” audit event without “FileDownloaded.” Investigators should assess access methods and surrounding evidence before ruling out acquisition.

Key points

  • LevelBlue’s controlled testing successfully retrieved Microsoft 365 file content while the Unified Audit Log recorded “FileAccessed” rather than “FileDownloaded.”
  • The article describes phishing and vishing-led account access followed by automated file exfiltration as a current threat pattern.
  • Programmatic access through Microsoft Graph, APIs, scripts, or non-standard user agents may not produce the expected “FileDownloaded” event.
  • Investigators should consider access method, user agent, activity volume and speed, authentication context, source infrastructure, and surrounding threat activity.
  • “FileAccessed” alone neither proves nor rules out file acquisition; “FilePreviewed” also requires context and does not establish that the complete file was obtained.

Article Details

Defense Focus
Assess potential file acquisition during unauthorized Microsoft 365 access without relying exclusively on FileDownloaded audit events.
Detection Methods
  • Review FileAccessed events associated with Microsoft Graph, other APIs, and scripted or non-standard user agents.
  • Identify high-volume, rapid sequential file access, especially access to numerous files within seconds or minutes and patterns inconsistent with normal interactive behavior.
  • Correlate file access with preceding file enumeration, search, or reconnaissance.
  • Correlate file events with suspicious source IP addresses, authentication context, and confirmed or suspected periods of unauthorized account access.
  • Evaluate FilePreviewed separately: thumbnail rendering and browser prefetch can generate preview events without acquisition of the complete file.
Data Sources
  • Microsoft 365 Unified Audit Log events, including FileAccessed, FileDownloaded, and FilePreviewed
  • User agent strings and access-method evidence
  • File-access volume, timing, and sequence
  • Authentication context and evidence of unauthorized account access
  • Source IP addresses and surrounding threat activity
  • Digital forensic artifacts relevant to file retrieval
Defensive Actions
  • Do not treat the absence of FileDownloaded events as evidence that file acquisition did not occur.
  • Assess FileAccessed activity during unauthorized access using access method, user agent, volume, velocity, authentication context, and surrounding threat activity.
  • Treat scripted or programmatic FileAccessed patterns as potential file acquisition when supported by the surrounding evidence.
  • Do not treat FileAccessed or FilePreviewed alone as proof that complete files were acquired.
  • Account for logging limitations and the totality of forensic evidence when making data-exposure assessments.

MITRE ATT&CK

Threat Actors

Vendors

Products

Related Articles