Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1204 ✕
Download CSV Show ATT&CK heatmapUncommon URL domain(s) in your organization detected in email Informational Email 3 variations
We have identified unpopular domain(s) in URL(s) within this email.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001) Execution (TA0002)ATT&CK techniques: Phishing (T1566) User Execution (T1204)Required data: Microsoft 365 EmailsDetector tags: Malicious URLsAttacker's goals: Trick the user into engaging with a URL(s), aiming to extract information or establish access to the network.Investigative actions: Examine the sender's IP address and reputation. Verify whether the sender's IP address has appeared in different log sources before and if it is recognizable. If the message contains attachments or links, scrutinize them for any suspicious indications. Monitor further actions taken, such as file downloads or access to potentially malicious links.Variations
External email with a first-seen URL domain(s) in your organization in the last 30 days
Informational overridden
We have identified unpopular domain(s) in URL(s) within this email. overridden
Internal email with a first-seen URL domain(s) in your organization in the last 30 days
Informational overridden
We have identified unpopular domain(s) in URL(s) within this email. overridden
Outbound email with a first-seen URL domain(s) in your organization in the last 30 days
Informational overridden
We have identified unpopular domain(s) in URL(s) within this email. overridden