Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Unusual attachment volume in outbound emails Informational Email 2 variations

    Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Hour
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Required data: Microsoft 365 Emails
    Detector tags: Exfiltration
    Attacker's goals: Extracting valuable information outside the company. Bypass Data Loss Prevention (DLP) by splitting data across multiple emails.
    Investigative actions: Check the content of the email that was sent. Review the external recipient address and assess its reputation. Review past emails sent from this mailbox for any suspicious activity. Check for unusual emails sent to this recipient's address. Monitor further action taken, such as accessing to private keys, API tokens and sensitive data.

    Variations

    Unusual attachment volume in outbound emails to a single external recipient

    Informational overridden

    Numerous emails with substantial attachments sent by internal sender to one external recipient within a short timeframe. overridden

    Unusual attachment amount and size in outbound emails

    Informational overridden

    Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe. overridden