Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0005 ✕

Download CSV Show ATT&CK heatmap
  • User moved Exchange sent messages to deleted items Informational Identity Threat Module, SaaS Threat Detection, Email 1 variation

    A user moved sent messages to deleted items in Exchange.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Indicator Removal: Clear Mailbox Data (T1070.008)
    Required data: Office 365 Audit
    Attacker's goals: An attacker is attempting to hide newly sent email messages for evasion purposes.
    Investigative actions: Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.

    Variations

    Sensitive Exchange sent messages moved to deleted items from unusual source

    Low overridden

    A user moved sensitive sent messages to deleted items in Exchange. overridden