Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Exchange email-hiding inbox rule Informational Identity Threat Module, SaaS Threat Detection, Email 3 variations

    A user configured an Exchange inbox rule that may be used to hide emails.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Hide Artifacts: Email Hiding Rules (T1564.008)
    Required data: Office 365 Audit
    Attacker's goals: Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).
    Investigative actions: Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule keywords look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for multiple instances of email hiding, which may be an indication of a larger campaign. Check if the user regularly configures inbox rules.

    Variations

    Possible BEC Exchange email-hiding inbox rule

    Medium overridden

    A user configured an Exchange inbox rule that may be used to hide emails. The rule contains characteristics that resemble a business email compromise (BEC) attack. overridden

    Suspicious Exchange email-hiding inbox rule

    Medium overridden

    A user configured an Exchange inbox rule that may be used to hide emails. The rule hides emails that contain suspicious keywords, which may be a sign of a compromised account. overridden

    Abnormal Exchange email-hiding inbox rule

    Low overridden

    A user configured an Exchange inbox rule that may be used to hide emails. overridden