Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0002 ✕ technique: T1036 ✕
Download CSV Show ATT&CK heatmapEmail attachment with Right-to-Left Override Unicode character Low Email
The email message contains an attachment with a hidden Right-to-Left Override Unicode character.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour 30 Minutes
ATT&CK tactics: Stealth (TA0005) Execution (TA0002)ATT&CK techniques: Masquerading: Masquerade File Type (T1036.008) User Execution (T1204)Required data: Microsoft 365 EmailsDetector tags: EvasionAttacker's goals: Bypass security filters and deliver malicious content to users Mislead recipients into opening a malicious file by obscuring its true nature Deploy malicious attachments through emails to compromise systems, gain unauthorized access, or facilitate cyber threats.Investigative actions: Carefully analyze attachments for any indications of suspicious or malicious behavior. Scrutinize the attachments for any suspicious indications. Confirm whether the attachments were successfully delivered to the recipient's mailbox. If the attachments were delivered successfully, verify whether the recipient downloaded them.