Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1564 ✕
Download CSV Show ATT&CK heatmapExchange email-hiding transport rule Informational Identity Threat Module, SaaS Threat Detection, Email 2 variations
A user configured an Exchange transport rule that may be used to hide emails in the organization.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Hide Artifacts: Email Hiding Rules (T1564.008)Required data: Office 365 AuditAttacker's goals: Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).Investigative actions: Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule contains keywords and if they look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization.* Look for multiple instances of email hiding, which may be an indication of a larger campaign.* Check if the user regularly configures transport rules.Variations
Suspicious Exchange email-hiding transport rule
Medium overridden
A user configured an Exchange transport rule that may be used to hide emails in the organization. The rule hides emails that contain suspicious keywords, which may be a sign of a compromised account. overridden
Exchange email-hiding transport rule based on message keywords
Low overridden
A user configured an Exchange transport rule that may be used to hide emails in the organization. The rule hides emails that contain certain keywords, which may be a sign of a compromised account. overridden