Dropbox monitoring / alerting

I am looking for how others have used or setup Rapid7 to monitor and/or alert on dropbox related “things”. Things like - large file upload or download, access to non-approved dropbox accounts, personal v business, new user or unauthorized user accessing dropbox personal or business. or anything else you feel should be monitored and or tracked.

You have three options within InsightIDR

  1. Search DNS for any activity relating to Dropbox queries. Something like where(“top_private_domain” = “dropbox.com”) would be a good starting point
  2. Look for any Investigations associated with Attacker Technique - Exfiltration Of Data To Dropbox. This looks out for any process activity which is trying to connect to Dropbox APIs
  3. If you have sensors deployed with ENTA enabled, you can search for any flow records associated with Dropbox. This is the only way you will see data transfer volumes. It cannot tell the difference between personal vs business as both hit the same Dropbox endpoints. See screenshot for an example of a flow record.

Screenshot 2024-01-15 at 14.57.26
Screenshot 2024-01-15 at 14.56.08

