Analytics BIOC Low

Sending unusual file(s) to an external address

Unusual files sent to an external address.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Initial Access (TA0001) Exfiltration (TA0010)
ATT&CK techniques: Phishing (T1566) Exfiltration Over Alternative Protocol (T1048)
Detector tags: Exfiltration
Attacker's goals:

Extracting sensitive credentials, potentially leading to account takeover or unauthorized access to internal services. Extracting valuable information outside the company.

Investigative actions:

Check the content of the unusual files that were sent. Review the external recipient address and assess its reputation. Review past emails sent from this mailbox for any suspicious activity. Check for unusual emails sent to this recipient's address. Monitor further actions taken, such as accessing private keys, API tokens and sensitive data.

Test period:
N/A (single event)
Deduplication:
1 Hour 30 Minutes