Dropbox is a file hosting service that offers cloud storage, file synchronization and personal cloud services. Dropbox allows its users access to files and folders anytime from desktop, web and mobile clients or even through applications connected to Dropbox. This presents a huge challenge for enterprises to closely monitor daily activities and look for malicious file activity, ex filtration of data.unauthorized file access, sharing, etc.
RSA Netwitness Plugin framework can be used to connect to Dropbox via API v2 to collect all user activity. Here are some of the common scenarios that can be monitored using this integration:
For more details on what can be collected please refer to this link: https://www.dropbox.com/developers/documentation/http/teams#team_log-get_events
Here are some of the use-cases that can be built on NetWitness Platform:
Reports/Dashboards:
1. Content Sharing Activity (Internal vs External)
2. Login Activity from various localities
3. Top 10 File Uploaded/Downloaded
4. Third-Party App activity.
5. Summary of File activity per user
6. Top User Activities
Alerts:
1. Login from suspicious Locality
2. Rapid Renames of Files
3. Sharing of file with more than the allowed number of users
4. External Sharing of Business sensitive files
Combined with the complete visibility that the RSA NetWitness Platform delivers for threat detection and response across logs, network, and endpoints for both private and public cloud environments – securing the cloud is simplified.
Downloads and Documentation:
Configuration Guide: https://community.rsa.com/docs/DOC-88467
Collector Package on RSA Live: "Dropbox"
Parser on RSA Live: CEF (device.type="dropbox")
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.