Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapRare DLP rule match by user Informational Identity Threat Module, SaaS Threat Detection, Email 1 variation
A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Data from Information Repositories: Sharepoint (T1213.002) Data from Information Repositories (T1213)Required data: Office 365 AuditDetector tags: O365 DLP AnalyticsAttacker's goals: An attacker is attempting to access sensitive information.Investigative actions: Review the details of the triggered DLP rule match. Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Communicate with the user to verify the legitimacy of the triggered event.Variations
DLP rule match by user for the first time
Low overridden
A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. overridden