Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Suspicious activity indicating a potential abuse of a cloud-native email service Low Cloud 2 variations

    A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    3 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Required data: AWS Audit Log Azure Audit Log
    Attacker's goals: Adversaries may use cloud-based email services to send phishing or spread malware, abusing legitimate email domains.
    Investigative actions: Check if the identity intended to preform these actions or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

    Variations

    Suspicious activity indicating a potential abuse of a cloud-native email service involving discovery, weaponization, and impact

    High overridden

    A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. The behavior that was observed included discovery operations, attack preparation and actual email sending. These activities might indicate an intent to abuse the email service to send phishing or spam. overridden

    Suspicious activity indicating a potential abuse of a cloud-native email service involving discovery and weaponization

    Medium overridden

    A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. The behavior that was observed included discovery operations and attack weaponization. These activities might indicate an intent to abuse the email service to send phishing or spam. overridden