Analytics
Informational
✕
Sensitive Exchange mail sent to external users
A user sent sensitive email messages to external users.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
- Licensed by:
- Identity Threat Detection (ITDR)
- Licensed by:
- Email Security
- Data source:
- Office 365 Audit
ATT&CK tactics: Collection (TA0009) Exfiltration (TA0010)
ATT&CK techniques: Email Collection (T1114) Exfiltration Over Alternative Protocol (T1048)
Detector tags: O365 DLP Analytics
Attacker's goals:
An attacker is attempting to collect sensitive email information.
Investigative actions:
Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
2 variations:
- Exchange mail to external account matching high severity DLP rules Low (parent: Informational)
- Sensitive Exchange mail sent to an external user Low (parent: Informational)