Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapOutbound email contains file-sharing service link sent to external recipient Informational Email 2 variations
Identifies outbound emails that include links to file-sharing services sent externally.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour 30 Minutes
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)ATT&CK techniques: User Execution (T1204) Brute Force: Password Cracking (T1110.002)Required data: Microsoft 365 EmailsDetector tags: ExfiltrationAttacker's goals: Exfiltrate data by sharing a link to a file-sharing service with external recipients, bypassing attachment inspection and potentially evading visibility controls.Investigative actions: Review the shared URL to determine if the file is publicly accessible or shared outside the organization. Check if the file-sharing domain has been previously used by this sender or others in the organization. Investigate recent outbound emails for similar use of file-sharing services or unusual external recipients.Variations
Outbound email to external recipient(s) uses first-seen for organization file-sharing service
Informational overridden
Identifies outbound emails that include links to file-sharing services sent externally. overridden
Outbound email to external recipient(s) uses first-seen for sender file-sharing service
Informational overridden
Identifies outbound emails that include links to file-sharing services sent externally. overridden