M365 PUR-IP-E5 Mappings

Defender for Cloud Apps file policies allow you to enforce a wide range of automated processes. Policies can be set to provide information protection, including continuous compliance scans, legal eDiscovery tasks, and DLP for sensitive content shared publicly.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
PUR-IP-E5 Information Protection Technique Scores T1087 Account Discovery
PUR-IP-E5 Information Protection Technique Scores T1087.004 Cloud Account
PUR-IP-E5 Information Protection Technique Scores T1119 Automated Collection
PUR-IP-E5 Information Protection Technique Scores T1020 Automated Exfiltration
PUR-IP-E5 Information Protection Technique Scores T1530 Data from Cloud Storage
PUR-IP-E5 Information Protection Technique Scores T1048 Exfiltration Over Alternative Protocol
PUR-IP-E5 Information Protection Technique Scores T1567 Exfiltration Over Web Service
PUR-IP-E5 Information Protection Technique Scores T1567.004 Exfiltration Over Webhook
PUR-IP-E5 Information Protection Technique Scores T1546 Event Triggered Execution
PUR-IP-E5 Information Protection Technique Scores T1070 Indicator Removal
PUR-IP-E5 Information Protection Technique Scores T1552 Unsecured Credentials
PUR-IP-E5 Information Protection Technique Scores T1552.008 Chat Messages