Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0009 ✕ technique: T1114 ✕
Download CSV Show ATT&CK heatmapSAAS - Email was reported by the user or administrator as a phishing attempt Informational Email 2 variations
An email reported by the user or administrator as a phishing attempt has been detected.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Email Collection (T1114)Required data: Office 365 AuditAttacker's goals: Trick the user into interacting with a malicious email by disguising it as legitimate, potentially leading to credential theft, malware infection, or data exfiltration.Investigative actions: Analyze the sender's IP address and domain reputation. Check if the sender has appeared in other logs or alerts across the organization. Review any URLs or attachments for signs of phishing, malware, or command-and-control communication. Correlate user actions (e.g., link clicks, file downloads) to assess potential compromise. Determine whether similar emails were sent to other users to identify a broader campaign.Variations
SAAS - Phishing report with suspicious verdict on internal domain sender
Low overridden
An email with an internal sender domain was reported as a phishing attempt.This may indicate either a compromised internal account or an external attacker impersonating an internal user. overridden
SAAS - Phishing report with with suspicious verdict
Low overridden
An email with a Malware/Block verdict reported by the user or administrator has been detected. overridden