Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1562 ✕

Download CSV Show ATT&CK heatmap
  • Microsoft 365 DLP policy disabled or removed Informational Identity Threat Module, SaaS Threat Detection, Email 1 variation

    A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses (T1562) Impair Defenses: Disable or Modify Tools (T1562.001)
    Required data: Office 365 Audit
    Attacker's goals: An attacker is attempting to bypass Microsoft 365 Data Loss Prevention (DLP) policies.
    Investigative actions: Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Monitor the user's activity for any access to sensitive data or data exfiltration. Investigate if any other security policies have been changed or removed.

    Variations

    Rare Microsoft 365 DLP policy removal

    Low overridden

    A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. overridden