Fluency Security Case Investigation

Case Investigation — john.smith@acme.example

A first-time SSN DLP trigger alongside a large SharePoint/OneDrive file movement, read against the full 767-event record and resolved into a quantified two-sided verdict.

Acme Corp (acme) · Cluster username_john.smith@acme.example_20260529 · 29 May 2026, 16:34–22:28 UTC (~6h) · Status NEW · Incident: true · 4 behavior rules / 11 cluster hits

11,600
Risk score · >8000Critical
4
Behavior rules fired
767
Underlying events
2
SSN DLP matches
~6h
Activity window
01 — What fired

Four behavior rules clustered on one user: an Exchange DLP match on possible US SSN content, a burst of OneDrive/SharePoint uploads, repeated file access, and the sign-in context around them.

02 — The record

767 events across SharePoint, Exchange and Azure AD — 207 uploads, 205 downloads, 82 mailbox accesses, full OneDrive syncs, and a single site-collection admin grant.

03 — Where it lands

The shape fits data staging and it fits ordinary remote-employee sync. Three checks separate the two, and none of them are in the record as captured.

Executive summary

User john.smith triggered an Exchange DLP policy for US SSN content for the first time in 30 days (ML_NEW_USER) while moving a large volume of files through SharePoint/OneDrive — 207 uploads, 205 downloads, full OneDrive syncs — which also raised a bandwidth anomaly. Eighty-two mailbox accesses and a single SharePoint site-collection admin grant occurred in the same window. Sign-ins came over consumer ISPs (T-Mobile, Comcast) from two US cities.

The behavioural shape is consistent with data staging and egress, but it is equally consistent with ordinary OneDrive sync by a remote employee.

Net read — lean benign, not closeable

The evidence does not support escalation on its own, and it does not support closure either. Three checks decide it: external-sharing activity in the window, the site-collection admin grant, and whether the two-geo login is concurrent or sequential.

Fluency AI Assistant — findings already on the case

The case arrived with an AI triage comment (validation: true, actionable: true). It assessed a first-time SSN DLP trigger with multiple SharePoint/OneDrive uploads and accesses, and flagged three anomalies: first-seen SSN DLP for this user in 30 days, multiple file uploads, multiple file accesses.

What the AI triage could not resolve

It found no contradiction between the alert and the events, but noted that missing IP and location context limits investigation. No mitigation was applied. It left five open questions — user intent, whether the activity fits the user's job, any external exposure, DLP follow-up and education, and possible account compromise.

The analysis below extends that triage with the full record composition, an ATT&CK mapping, the detection gaps, and the quantified two-sided verdict it did not provide.

MITRE ATT&CK mapping

Inferred from signatures & activity
TacticTechniqueDriver (signal / activity)Basis
Initial AccessT1078.004 Cloud AccountsO365_AzureAD_UserLoggedIn over T-Mobile + Comcast, 2 cities, Chrome/Win10Signature + activity
Priv. EscalationT1098.003 Additional Cloud RolesSiteCollectionAdminAdded (1) — SharePoint admin grant in-windowActivity
CollectionT1530 Data from Cloud Storage205 FileDownloaded + O365_SharePoint_FileAccessed_MultipleSignature + activity
CollectionT1114 Email Collection82 MailItemsAccessed (Audit.Exchange)Activity
ExfiltrationT1567.002 Exfil to Cloud Storage207 FileUploaded + FileSyncUploadedFull + BANDWIDTH_ANOMALYSignature + activity
Sensitive dataO365_DLP_Policy_SSNExchange DLP — possible US SSN content (ALERT_POLICY)Signature

What's in the records

767 events in the capture window.

Top operations

FileUploaded
207
FileDownloaded
205
FolderBind
181
MailItemsAccessed
82
FileAccessed
27
FolderCreated
22
FileModified
7
UserLoggedIn
7

Source workload

SharePoint
495
Exchange
263
Azure AD
7
DLP (SSN)
2

SharePoint 65% · Exchange 34% of the 767 events. Ink tints carry series only — no colour encoding.

Record detail

ElementDetail from the record
Identityjohn.smith@acme.example (named employee)
Sign-inChrome / Windows 10 · OAuth2:Authorize · 7 logins
NetworksISPs T-Mobile USA & Comcast; ActorIPs 2607:fb91:802:1645:…, 2601:152:4f80:8420:… (IPv6)
GeoCities Metro A & Metro B, United States (~1,300 mi apart, same window)
Risk flagsALERT_POLICY · ML_NEW_USER · BANDWIDTH_ANOMALY · FILE_DOWNLOAD
Notable single eventsSiteCollectionAdminAdded · 4× DLPRuleMatch · FileSyncUploadedFull/DownloadedFull
DLP event gapExchange DLP hit carried no IP / city / country (__undefined)

What we did alert on

Behavior ruleSub-scoreRisk flagsWhat it caught
O365_DLP_Policy_SSN4,400ALERT_POLICY ML_NEW_USERExchange DLP match on possible US SSN; first-seen for this user
O365_SharePoint_OneDrive_FileUploaded_Multiple1,000ALERT_POLICY BANDWIDTH_ANOMALYBurst of uploads to OneDrive/SharePoint
O365_SharePoint_FileAccessed_Multiple200FILE_DOWNLOAD ALERT_POLICYRepeated file access/download over ~5.5h
O365_AzureAD_UserLoggedIn0Sign-in context (ISP / city / device)

What we could have alerted on

Detection gaps surfaced by this case.

Verdict — issue vs. benign

True positive 35% Benign / false positive 65%

Likely a real issue — ~35%

  • SSN DLP genuinely fired — sensitive data is confirmed present, not hypothetical.
  • First-seen behavior (ML_NEW_USER) — a deviation from this user's 30-day baseline.
  • Bandwidth anomaly + 207 uploads / 205 downloads + full syncs — the shape of staging and egress.
  • SiteCollectionAdminAdded in-window — a privilege change expected in takeover or insider staging.
  • Two metros over two consumer ISPs in one window — consistent with a shared or compromised credential.
  • Asymmetric risk: because the data is SSNs, even a low probability warrants confirmation.

Likely benign — ~65%

  • All operations are normal O365 productivity; the upload/download/FileSyncUploadedFull mix is the textbook signature of a OneDrive client syncing.
  • No external or anonymous sharing, no foreign geo, no anonymizer, no malware — US-only over ordinary home and mobile ISPs.
  • Named employee; construction firms routinely handle subcontractor SSNs and certified payroll, making SSN DLP a high-false-positive detector.
  • ML_NEW_USER only means "first hit in 30 days" — a weak signal.
  • The two-city pattern is readily explained by T-Mobile mobile (poor IPv6 geo) plus Comcast home; same browser and OS.
  • Fluency AI triage: "no contradictions, but lacking context" — unresolved, not malicious.

Recommended next steps

Evidence is preserved in scenario scn-n5gkgzkuueww4 for detection testing against the gaps above.

Methodology

Source. Read-only analysis via the Fluency MSSP MCP (get_case full record and create_scenario_from_case capture summary, 767 sanitized events).

Mapping basis. MITRE ATT&CK tactics and techniques are inferred from the firing signatures and observed O365 operations — the signature catalog carries no formal ATT&CK tags.

Verdict. Likelihoods are an analyst estimate from the evidence present and are not a Fluency output.

Identity. Preserved per MCP redaction policy. Case username_john.smith@acme.example_20260529, tenant acme. Sanitized for external sharing — customer and tenant names, users, hostnames and domains replaced with training identities; IPs, hashes, CVE and technique IDs and event IDs preserved as IOCs.

Generated 5 June 2026.