Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0002 ✕
Download CSV Show ATT&CK heatmapEmail with file-sharing link containing auto-download parameter Low Email 1 variation
The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour 30 Minutes
ATT&CK tactics: Initial Access (TA0001) Execution (TA0002)ATT&CK techniques: Phishing: Spearphishing Link (T1566.002) User Execution: Malicious File (T1204.002)Required data: Microsoft 365 EmailsDetector tags: Malicious URLsAttacker's goals: The attacker may be attempting to deliver malware or exfiltrate data using auto-download file-sharing links.Investigative actions: Analyze the linked file(s) to determine if they pose any security risk. Check the sender's communication history within the organization. Analyze the file reputation using sandbox or threat intelligence sources. Verify whether similar links were sent to other users.Variations
External email with file-sharing link containing auto-download parameter
Low overridden
The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download. overridden