Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Cloud email service activity Informational Cloud 2 variations

    A cloud Identity performed an email service operation.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Internal Spearphishing (T1534)
    Required data: AWS Audit Log Azure Audit Log
    Attacker's goals: Abuse the cloud email service for sending phishing emails.
    Investigative actions: Check for any following actions related to this activity. Verify that the identity did not abuse the email service to send phishing emails to victims.

    Variations

    Unusual cloud email service activity

    Low overridden

    A cloud Identity performed an email service operation for the first time in the tenant. overridden

    Cloud email service entity creation

    Low overridden

    A cloud Identity created a new cloud email identity. overridden