Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0009 ✕

Download CSV Show ATT&CK heatmap
  • Exchange compliance search created Informational Identity Threat Module, SaaS Threat Detection, Email 2 variations

    A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Email Collection (T1114)
    Required data: Office 365 Audit
    Attacker's goals: An attacker is searching mailboxes to access sensitive information.
    Investigative actions: Follow further actions done by the account. Check to see if the search contained sensitive information. Check if any data was exfiltrated after the search. Look for suspicious search terms.

    Variations

    Suspicious Exchange compliance search created

    Low overridden

    A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. The query contains potentially suspicious keywords, which could indicate an attempt of sensitive data collection. overridden

    Exchange compliance search created for the first time

    Low overridden

    A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. overridden