Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapSuspicious activity indicating a potential abuse of a cloud-native email service Low Cloud 2 variations
A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 3 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)Required data: AWS Audit Log Azure Audit LogAttacker's goals: Adversaries may use cloud-based email services to send phishing or spread malware, abusing legitimate email domains.Investigative actions: Check if the identity intended to preform these actions or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).Variations
Suspicious activity indicating a potential abuse of a cloud-native email service involving discovery, weaponization, and impact
High overridden
A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. The behavior that was observed included discovery operations, attack preparation and actual email sending. These activities might indicate an intent to abuse the email service to send phishing or spam. overridden
Suspicious activity indicating a potential abuse of a cloud-native email service involving discovery and weaponization
Medium overridden
A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. The behavior that was observed included discovery operations and attack weaponization. These activities might indicate an intent to abuse the email service to send phishing or spam. overridden