Analytics BIOC Informational

Outbound email contains file-sharing service link sent to external recipient

Identifies outbound emails that include links to file-sharing services sent externally.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
ATT&CK techniques: User Execution (T1204) Brute Force: Password Cracking (T1110.002)
Detector tags: Exfiltration
Attacker's goals:

Exfiltrate data by sharing a link to a file-sharing service with external recipients, bypassing attachment inspection and potentially evading visibility controls.

Investigative actions:

Review the shared URL to determine if the file is publicly accessible or shared outside the organization. Check if the file-sharing domain has been previously used by this sender or others in the organization. Investigate recent outbound emails for similar use of file-sharing services or unusual external recipients.

Test period:
N/A (single event)
Deduplication:
1 Hour 30 Minutes
2 variations:
  • Outbound email to external recipient(s) uses first-seen for organization file-sharing service Informational
  • Outbound email to external recipient(s) uses first-seen for sender file-sharing service Informational