Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To investigate a SharePoint ransomware alert, establish the incident window and affected scope, check whether file changes are still syncing, then correlate SharePoint audit records with Microsoft Entra sign-ins and available endpoint evidence. Treat each source as a piece of the timeline—not as proof of attribution on its own.

What to establish first

Begin with the alert and the incident timeline. Microsoft’s Ransomware response guidance emphasizes assessing the situation and scope, including when the organization first detected the incident, which logs are available, and whether an attacker may still have access. Record findings as the investigation proceeds so they can inform containment and recovery.

  • When the organization first learned of the incident, what generated the alert, and the first known suspicious activity.
  • Potentially affected accounts, SharePoint sites, libraries, files, devices, and applications.
  • Whether suspicious access or file changes appear to be continuing.
  • Available evidence sources, the people responsible for collecting and reviewing them, and any containment already taken.

Maintain a timeline that records each event’s timestamp and timezone, source system, account or application identity, operation, target site or file, IP address or session context where available, collection method, and analyst interpretation. Mark observations separately from hypotheses; for example, an unfamiliar IP address is an observation, while the claim that it identifies an attacker is a hypothesis.

Could ransomware changes still be reaching SharePoint?

Stop the synchronization path described by Microsoft

Microsoft’s Handling ransomware in SharePoint Online describes ransomware running locally and changing files through a mapped SharePoint library or a OneDrive connection, after which the client or WebDAV can synchronize those changes to the cloud. For this scenario, Microsoft advises immediately stopping OneDrive sync or disconnecting the mapped SharePoint drive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

This interrupts that endpoint’s potential file-propagation path; it does not establish that the account, tenant, or other devices are safe. Coordinate broader network isolation, account containment, token revocation, and evidence preservation through the incident lead. Microsoft’s enterprise response guidance calls for containment in light of incident scope; the appropriate actions depend on the conditions of the incident.

Check whether the file pattern fits

Microsoft lists several possible SharePoint Online ransomware signs. Use them to identify files and time windows for validation, not as stand-alone proof of who acted or how access began.

  • Many library files show the same Modified By timestamp.
  • Files fail to open or appear corrupted.
  • Ransom instructions appear in directories; Microsoft gives HELP_DECRYPT and HELP_Recover as examples.
  • Files have been renamed or given an appended extension.
  • Files appear to have been encrypted or deleted before affected versions synchronized online.

Compare suspected changes with audit records, file history, endpoint evidence, and the alert’s details. A shared timestamp can help define a search window, but by itself it does not identify an actor or explain the route of access.

Rank #2
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
  • Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Which evidence sources answer which questions?

Use the sources together. Their value depends on what records exist for the incident and what the tenant retained and made available.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Evidence source What it can help establish Important limitation
Microsoft Purview Audit Recorded SharePoint and OneDrive file, page, site, and permission-related operations, including the affected object and recorded actor context. Search results depend on access scope, tenant configuration, record availability, and retention. A summarized activity label may not expose all useful detail.
Microsoft Entra sign-in records Sign-in time, IP address, location, and success or failure around the suspicious period; risk information may also help assess identity activity. An IP address or location alone does not prove who used an account. Compare with the user’s expected devices, travel, VPN use, authentication result, and corresponding file operations.
Endpoint or Defender evidence, where available Context about activity on a device and related security detections that can be compared with cloud events. Availability and time coverage depend on the organization’s tools and configuration; these records do not replace SharePoint or identity records.

Microsoft’s Audit log activities catalog documents SharePoint and OneDrive file, page, and site-related activity. Relevant file operations include accessing, creating or uploading, modifying, downloading, moving, renaming, and deleting content. Review site administration and permission changes too when the suspected activity could involve expanded access or persistence.

How to search and review Purview audit records

Search broadly enough to find the start of the activity

In Microsoft Purview Audit, search a date range that begins before the suspected suspicious activity. Microsoft’s compromised-account response guidance recommends starting immediately before that activity and initially avoiding a narrow activity filter. This gives you room to find related events whose operation or timing was not known when the search began.

Rank #3
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
  • Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Refine the results using the time window, user, site or file, and operation as evidence permits. Review SharePoint results alongside relevant Entra sign-in data and Defender audit records where available. Export the results for detailed review and preserve the search parameters and collection time with the evidence.

Inspect record details, not just the activity name

Review detailed record fields and the context around each operation. Some SharePoint audit records show app@sharepoint as the actor because an application performed the action on behalf of a user, administrator, or service. Do not treat that displayed value alone as the human identity; interpret it with the record’s delegated context and any corresponding identity evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build the event sequence around consequential file and site operations. Note clusters of changes, the affected targets, and whether the records align with the suspected encryption or deletion window. Preserve the exported records and document how they were collected so another responder can understand the basis for the timeline.

Rank #4
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
  • Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

How to correlate SharePoint activity with account sessions

Review Microsoft Entra sign-in IP address, location, time, and success or failure around the suspicious window. Microsoft recommends reviewing sign-in and risk information from the onset of suspicious activity through remediation. Compare identity events with the relevant SharePoint operations rather than assessing a sign-in in isolation.

Microsoft documents linking Entra sign-in identifiers—including the session ID (SID) and unique token identifier (UTI)—with corresponding SharePoint audit fields such as AADSessionId and UniqueTokenId. When those identifiers are present, searching for a matching session or token identifier can help connect file operations to a particular session. The linkage is useful only to the extent that the relevant records and fields are available.

If token theft is suspected, Microsoft’s guidance describes revoking active sessions or tokens as a containment measure followed by forensic review. Make that decision under the response team’s authority and evidence-preservation process. Do not attribute activity to a person solely because their account appears in a record, or because a sign-in came from an unfamiliar location.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
UnionSine 500GB Ultra Slim Portable External Hard Drive HDD-USB 3.0
  • [Upgraded Version] - This external hard drive features a mirrored logo stripe combined with a striped anti-slip design, and the rounded corners of the casing make it easier to grip. The stripes also have a heat dissipation function, ensuring stable and fast data transfer.
  • 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
  • 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
  • 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
  • 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does a missing audit event mean?

A search with no matching result does not by itself prove that an action did not happen. Before treating an empty result as evidence that activity was absent, check that the investigator could search and export the relevant records, that the search was not restricted to the wrong administrative-unit scope, and that the records fall within the tenant’s configured retention and available data.

Confirm audit access and scope

Microsoft says Purview audit search requires the Audit Logs or View-Only Audit Logs role. Audit Manager and Audit Reader role groups are documented default ways to grant those roles. Administrative-unit scoping can restrict an investigator’s search and export results, so confirm both the assigned role and the applicable scope.

Verify the tenant’s retention settings

Microsoft’s Get started with auditing solutions documentation describes 180-day searchable retention in Audit Standard and Audit Premium. It also describes a default one-year retention policy for specified Microsoft Entra ID, Exchange, OneDrive, and SharePoint audit records with Audit Premium; Premium can use configured retention policies. These are service documentation defaults, not confirmation of a particular tenant’s license, settings, or record coverage. Verify the tenant’s actual configuration and policy before drawing conclusions from the search window.

What should the incident handoff and recovery decision include?

Give the incident lead a concise, evidence-based account that another responder can use to decide what to contain or recover. Record affected sites and files, the observed operation sequence, relevant accounts and applications, sign-in and session context, earliest and latest observed events, containment already taken, evidence gaps, and the confidence level for each conclusion. Track owners, status, findings, dates, and times.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For affected content, Microsoft points administrators to SharePoint document library restore and OneDrive library restore procedures, and identifies Microsoft 365 Backup as another recovery option. These are service options, not evidence that a particular tenant has the service or configuration available. Verify recovery capabilities and coordinate restoration with incident responders so known-bad content is not restored and evidence needed for the investigation is not obscured.

Quick Recap

SaleBestseller No. 1
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.99
Bestseller No. 2
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$229.99
Bestseller No. 3
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.80
Bestseller No. 4
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$149.84

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.