Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • PowerShell used to remove mailbox export request logs High

    An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
    Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Remove evidence for mailbox export commands.
    Investigative actions: Examine the PowerShell command to identify which mailbox has been compromised. Investigate the host that executes the command for potential further exploitation.