Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • DLP sensitive data exposed to external users Informational Identity Threat Module, SaaS Threat Detection, Email 1 variation

    A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Data from Information Repositories: Sharepoint (T1213.002) Data from Information Repositories (T1213)
    Required data: Office 365 Audit
    Detector tags: O365 DLP Analytics, Data Detection & Response
    Attacker's goals: An attacker is attempting to access sensitive information.
    Investigative actions: Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.

    Variations

    High-severity DLP sensitive data exposed to external users

    Low overridden

    A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. overridden