Netwrix 1Secure delivers unified visibility across data and identity - free for 14 days with full access. Start a free trial

Resource centerBlog

Copilot broke your insider threat detection, and MITRE wrote the proof

Copilot broke your insider threat detection, and MITRE wrote the proof

Sep 24, 2026

MITRE ATT&CK's detection analytic for adversaries mining SharePoint describes bulk access to files and metadata in a short window by privileged or rarely used accounts. That is also a description of Microsoft 365 Copilot answering a question. The technique hasn't changed, but the baseline has, and the exposure now happens with no vulnerability, no compromised credential, and no malicious intent anywhere in the chain.

MITRE ATT&CK publishes a detection analytic, AN1380, for adversaries mining SharePoint for useful internal documents. It reads:

"Privileged or rarely used accounts performing bulk access to SharePoint files or metadata over a short time window, indicating potential scripted collection of sensitive internal documents."

That is also what Microsoft 365 Copilot does when someone asks it to summarize last quarter's contract negotiations.

Same behavior, same telemetry. One is technique T1213.002, data from information repositories: SharePoint. The other is a licensed employee doing their job.

No breach required

Every technique in ATT&CK assumes an adversary who had to get somewhere first. HAFNIUM, Ke3chang, and Chimera are state-sponsored espionage groups MITRE tracks by name, and all three show up in the procedure examples for this technique. HAFNIUM abused compromised credentials to exfiltrate SharePoint data. Ke3chang ran a purpose-built enumeration tool called spwebmember. Chimera collected documents after establishing access. Every one of them needed a way in.

Copilot needs none of that. No CVE, no stolen token, no tooling on a host, no policy violation. Nobody in the chain intends anything harmful and the consent was granted years ago by whoever configured inheritance on a site that no longer has an owner.

A technique created in February 2020 hasn't changed. What changed is the denominator. Bulk repository access used to imply a script, and a script used to imply somebody who shouldn't be there. Now every licensed user produces that pattern several times a day by typing a question in English.

Scattered Spider's reconnaissance is now a prompt

MITRE records that during campaign C0027, Scattered Spider accessed victim SharePoint environments "to search for VPN and MFA enrollment information, help desk instructions, and new hire guides." That reconnaissance is the homework before a help desk social engineering call.

Reaching this information used to require an attacker to breach the network. Now it’s available to anyone who can authenticate as an employee and ask the question: "what's our process when someone needs to re-enroll MFA?"

The intrusion version left traces like files accessed, systems probed, and artifacts on disk. The AI version leaves a question any new hire might ask.

There are two options, and most teams already picked one by accident

AI usage is so prevalent that IT or SecOps teams would be swamped by alerts on prompts that could be reconnaissance. This leaves them with two bad options:

Retune the detection. Raise the threshold, or exclude the agent's service principal. Coverage for T1213.002 quietly goes to zero, and the technique still works as well as it ever did.

Or leave it alone. Analysts triage AI activity all day, alert fatigue does what alert fatigue does, and the detection dies anyway.

Most organizations picked the first without deciding to. Somebody tuned out the noise during a busy week and nothing got written down. Audit your coverage against ATT&CK today and that cell is probably still green.

The attribution gap surfaces six months later, in an HR case

The audit log says a user's account accessed the compensation model. The user says they never opened it. Both can be true. The agent surfaced two lines of it inside a summary of something else.

Now investigate that. Intent separates an insider threat from an accident, and intent is what the log can no longer establish. Behavioral analytics make it harder, because those baselines assume human rhythm and the same account now emits machine-speed bursts. Normal widens for everybody, which leaves anomalous human behavior more room to sit unnoticed.

You've likely already deployed Copilot, so start with what it has already reached

Most existing guidance assumes you haven't turned it on yet. Here are three questions to ask once you have:

What can identities actually reach right now? Not permissions on paper, but the effective path: nested groups, inherited site permissions, sharing links that outlived their projects, guest accounts nobody has reviewed since onboarding.

What has AI-driven activity touched in the last 90 days? You need the record before you need the policy.

Which detections still treat bulk repository access as evidence of an adversary? Find them, and decide deliberately this time.

Netwrix 1Secure covers the first two. It discovers and classifies sensitive data across cloud and on-prem repositories, maps which identities can reach it and through which paths, and monitors AI-driven access against that picture. The third question has no defensible answer until you can answer the first two.

Copilot isn't the problem. It's doing what Microsoft said it would do, with permissions your organization approved. The problem is that your detection logic encodes an assumption that this pattern means an adversary, which quietly stopped being true, and nobody knew to open a ticket to revisit it.

Share on

Learn More

About the author

Asset Not Found

James Anderson

Technical Product Manager

James Anderson is a Technical Product Manager for Netwrix Access Analyzer and Netwrix Change Tracker. He has over 15 years of experience in software and data, including roles as Lead Data Engineer, Data Architect, and DBA.