Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1566 ✕
Download CSV Show ATT&CK heatmapUnusual display name in From header Informational Email 2 variations
An email was detected with an unusual display name in the From header.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Reconnaissance (TA0043) Initial Access (TA0001)ATT&CK techniques: Phishing for Information (T1598) Phishing (T1566)Required data: Microsoft 365 EmailsAttacker's goals: Evade defenses and hide potential malicious data inside the email display name.Investigative actions: Analyze the email further to determine the source of the anomaly and what can be done about it.Variations
Unusual display name in the From header containing an embedded URL
Low overridden
An email was detected with an unusual sender display name in the From header containing an embedded URL. overridden
Unusual display name in the From header that is identical to the email address
Informational overridden
An email was detected where the display name in the From header is unusual and matches the sender email address. overridden