Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • SAAS - Email was reported by the user or administrator as a phishing attempt Informational Email 2 variations

    An email reported by the user or administrator as a phishing attempt has been detected.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Email Collection (T1114)
    Required data: Office 365 Audit
    Attacker's goals: Trick the user into interacting with a malicious email by disguising it as legitimate, potentially leading to credential theft, malware infection, or data exfiltration.
    Investigative actions: Analyze the sender's IP address and domain reputation. Check if the sender has appeared in other logs or alerts across the organization. Review any URLs or attachments for signs of phishing, malware, or command-and-control communication. Correlate user actions (e.g., link clicks, file downloads) to assess potential compromise. Determine whether similar emails were sent to other users to identify a broader campaign.

    Variations

    SAAS - Phishing report with suspicious verdict on internal domain sender

    Low overridden

    An email with an internal sender domain was reported as a phishing attempt.This may indicate either a compromised internal account or an external attacker impersonating an internal user. overridden

    SAAS - Phishing report with with suspicious verdict

    Low overridden

    An email with a Malware/Block verdict reported by the user or administrator has been detected. overridden