Analytics BIOC Informational

Exchange compliance search created

A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Email Collection (T1114)
Attacker's goals:

An attacker is searching mailboxes to access sensitive information.

Investigative actions:

Follow further actions done by the account. Check to see if the search contained sensitive information. Check if any data was exfiltrated after the search. Look for suspicious search terms.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Suspicious Exchange compliance search created Low (parent: Informational)
  • Exchange compliance search created for the first time Low (parent: Informational)