Analytics BIOC Informational

Near-empty email from an external sender

The email was sent from an external sender and contains minimal content. Near-empty emails from external sources are uncommon and may be used to bypass content-based detection or prompt user interaction without clear context.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Reconnaissance (TA0043)
ATT&CK techniques: Gather Victim Identity Information (T1589)
Detector tags: Reconnaissance
Attacker's goals:

Attackers send reconnaissance emails to explore an organization's email security by verifying email address validity and testing spam filter effectiveness. The gathered information enables them to craft more precise and effective attacks, such as phishing or business email compromise (BEC).

Investigative actions:

Check the content of the body and whether it has any relevance to the recipients. Check the email address for any unusual spellings. Check the email address for any missing letters. Verify the sender's address to confirm its legitimacy. Check for previous emails from the sender's address. Verify whether the sender's IP address has appeared in different log sources before.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Blank email with an inline attachment from an external sender Informational
  • Blank email with an attachment from an external sender Informational
  • Empty email from an external sender Informational