Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0009 ✕
Download CSV Show ATT&CK heatmapExchange compliance search created Informational Identity Threat Module, SaaS Threat Detection, Email 2 variations
A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Email Collection (T1114)Required data: Office 365 AuditAttacker's goals: An attacker is searching mailboxes to access sensitive information.Investigative actions: Follow further actions done by the account. Check to see if the search contained sensitive information. Check if any data was exfiltrated after the search. Look for suspicious search terms.Variations
Suspicious Exchange compliance search created
Low overridden
A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. The query contains potentially suspicious keywords, which could indicate an attempt of sensitive data collection. overridden
Exchange compliance search created for the first time
Low overridden
A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. overridden