Analytics BIOC Informational

SAAS - Email was reported by the user or administrator as a phishing attempt

An email reported by the user or administrator as a phishing attempt has been detected.

Module:
Email Security
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Email Collection (T1114)
Attacker's goals:

Trick the user into interacting with a malicious email by disguising it as legitimate, potentially leading to credential theft, malware infection, or data exfiltration.

Investigative actions:

Analyze the sender's IP address and domain reputation. Check if the sender has appeared in other logs or alerts across the organization. Review any URLs or attachments for signs of phishing, malware, or command-and-control communication. Correlate user actions (e.g., link clicks, file downloads) to assess potential compromise. Determine whether similar emails were sent to other users to identify a broader campaign.

Test period:
N/A (single event)
Deduplication:
1 Hour
2 variations:
  • SAAS - Phishing report with suspicious verdict on internal domain sender Low (parent: Informational)
  • SAAS - Phishing report with with suspicious verdict Low (parent: Informational)