Analytics BIOC
Informational
✕
SAAS - Email was reported by the user or administrator as a phishing attempt
An email reported by the user or administrator as a phishing attempt has been detected.
- Module:
- Email Security
- Licensed by:
- Email Security
- Data source:
- Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Email Collection (T1114)
Attacker's goals:
Trick the user into interacting with a malicious email by disguising it as legitimate, potentially leading to credential theft, malware infection, or data exfiltration.
Investigative actions:
Analyze the sender's IP address and domain reputation. Check if the sender has appeared in other logs or alerts across the organization. Review any URLs or attachments for signs of phishing, malware, or command-and-control communication. Correlate user actions (e.g., link clicks, file downloads) to assess potential compromise. Determine whether similar emails were sent to other users to identify a broader campaign.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour
2 variations:
- SAAS - Phishing report with suspicious verdict on internal domain sender Low (parent: Informational)
- SAAS - Phishing report with with suspicious verdict Low (parent: Informational)