Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕ technique: T1070 ✕
Download CSV Show ATT&CK heatmapUser moved Exchange sent messages to deleted items Informational Identity Threat Module, SaaS Threat Detection, Email 1 variation
A user moved sent messages to deleted items in Exchange.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 10 Minutes
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Indicator Removal: Clear Mailbox Data (T1070.008)Required data: Office 365 AuditAttacker's goals: An attacker is attempting to hide newly sent email messages for evasion purposes.Investigative actions: Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.Variations
Sensitive Exchange sent messages moved to deleted items from unusual source
Low overridden
A user moved sensitive sent messages to deleted items in Exchange. overridden