Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0040 ✕

Download CSV Show ATT&CK heatmap
  • Massive files deletion in Box Informational Identity Threat Module 1 variation

    A user deleted a large amount of data in Box. This behavior may indicate that the data is being wiped.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Data Destruction (T1485)
    Required data: Box Audit Log
    Detector tags: Data Detection & Response
    Attacker's goals: An attacker may delete files from a SaaS service to wipe data from the organization.
    Investigative actions: Investigate the source account and verify if it was compromised or performed an authorized activity. Review the files that were deleted to determine if they contain sensitive or critical data. Monitor the account for any further suspicious actions.

    Variations

    Massive files deletion in Box with suspicious parameters

    Low overridden

    A suspicious user deleted a large amount of data in Box. This behavior may indicate that the data is being wiped. overridden