Analytics BIOC
Informational
✕
Outbound email contains file-sharing service link sent to external recipient
Identifies outbound emails that include links to file-sharing services sent externally.
- Module:
- Email Security
- Licensed by:
- Email Security
- Data source:
- Microsoft 365 Emails
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
ATT&CK techniques: User Execution (T1204) Brute Force: Password Cracking (T1110.002)
Detector tags: Exfiltration
Attacker's goals:
Exfiltrate data by sharing a link to a file-sharing service with external recipients, bypassing attachment inspection and potentially evading visibility controls.
Investigative actions:
Review the shared URL to determine if the file is publicly accessible or shared outside the organization. Check if the file-sharing domain has been previously used by this sender or others in the organization. Investigate recent outbound emails for similar use of file-sharing services or unusual external recipients.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour 30 Minutes
2 variations:
- Outbound email to external recipient(s) uses first-seen for organization file-sharing service Informational
- Outbound email to external recipient(s) uses first-seen for sender file-sharing service Informational