Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1566 ✕

Download CSV Show ATT&CK heatmap
  • Display text URL differs from actual URL Informational Email

    An email contains a hyperlink whose display text shows a URL different from the actual destination URL.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour 30 Minutes
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing (T1566)
    Required data: Microsoft 365 Emails
    Detector tags: Malicious URLs
    Attacker's goals: Deceive recipients into trusting a visible URL while redirecting them to a different destination, often for phishing, credential harvesting, or malware delivery.
    Investigative actions: Review the display text URL and the actual destination URL. Verify the reputation and legitimacy of the destination domain. Check whether the sender or domain is known or trusted within the organization.