Analytics Informational

Sensitive Exchange mail sent to external users

A user sent sensitive email messages to external users.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Collection (TA0009) Exfiltration (TA0010)
ATT&CK techniques: Email Collection (T1114) Exfiltration Over Alternative Protocol (T1048)
Detector tags: O365 DLP Analytics
Attacker's goals:

An attacker is attempting to collect sensitive email information.

Investigative actions:

Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.

Test period:
1 Hour
Deduplication:
1 Day
2 variations:
  • Exchange mail to external account matching high severity DLP rules Low (parent: Informational)
  • Sensitive Exchange mail sent to an external user Low (parent: Informational)