Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0003 ✕

Download CSV Show ATT&CK heatmap
  • Exchange mailbox delegation permissions added Informational Identity Threat Module, SaaS Threat Detection, Email 1 variation

    A user added delegation permissions to an Exchange mailbox.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    4 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation: Additional Email Delegate Permissions (T1098.002)
    Required data: Office 365 Audit
    Attacker's goals: Add delegation permissions to a mailbox for persistence reasons.
    Investigative actions: Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents).

    Variations

    Addition of Exchange mailbox delegation permissions with suspicious characteristics

    Low overridden

    A user added delegation permissions to an Exchange mailbox. overridden