The User Downloaded 4GB of Data Before Resigning
The user had not triggered an impossible travel alert.
MFA was still working.
No malware was detected.
The account behaved like a legitimate employee account.
But three days before resigning, the download volume changed completely.

Cloud Data Investigation
The identity looked normal. The volume did not.
Nothing looked obviously malicious
The first clue was not a file—it was the baseline
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
Typical daily download activity: 20 MB - 50 MB Three days before resignation: 4.2 GB Authentication alerts: None
Start with the user's cloud activity
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 8
- 9
CloudAppEvents
| where Timestamp > ago(30d)
| where AccountDisplayName == "Alex Morgan"
| project Timestamp,
Application,
ActionType,
ObjectName,
IPAddress,
RawEventData
Find the actions that represent file access
- 1
- 2
- 3
- 4
- 5
- 6
- 7
CloudAppEvents | where Timestamp > ago(30d) | where AccountDisplayName == "Alex Morgan" | summarize Events = count() by Application, ActionType | order by Events desc
Build a daily activity baseline
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
CloudAppEvents
| where Timestamp > ago(30d)
| where AccountDisplayName == "Alex Morgan"
| where ActionType has "download"
| summarize DownloadEvents = count()
by bin(Timestamp, 1d)
| order by Timestamp asc
Count is useful. Volume is better.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
CloudAppEvents
| where Timestamp > ago(30d)
| where AccountDisplayName == "Alex Morgan"
| where ActionType has "download"
| extend FileSizeBytes = tolong(RawEventData.FileSize)
| summarize DownloadedBytes = sum(FileSizeBytes),
DownloadEvents = count()
by bin(Timestamp, 1d)
| extend DownloadedGB = round(DownloadedBytes / 1024.0 / 1024.0 / 1024.0, 2)
| order by Timestamp asc

