Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0005 ✕

Download CSV Show ATT&CK heatmap
  • Unusual sender IP subnet Informational Email 2 variations

    This IP address has not been observed in correlation with the sender's fully qualified domain name within the last 30 days.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Social Engineering: Impersonation (T1684.001)
    Required data: Microsoft 365 Emails
    Detector tags: Spoofing
    Attacker's goals: Disguise the email's origin by spoofing the received header to appear as a trusted sender, impersonating a trusted source, aims to mislead recipients into disclosing private data or performing unsafe acts.
    Investigative actions: Review the email's received headers, to trace its path and spot spoofing signs. Examine the sender's IP address and domain reputation. Closely inspect the email content for malicious links, attachments, or requests for sensitive information. Monitor further actions taken, such as file downloads or access to potentially malicious links.

    Variations

    Unusual sender IP subnet associated with infrastructure or tunneling services

    Informational overridden

    This IP address has not been observed in correlation with the sender's fully qualified domain name within the last 30 days. overridden

    Unusual sender IP subnet associated with internal sender

    Informational overridden

    This IP address has not been observed in correlation with the sender's fully qualified domain name within the last 30 days. overridden