Analytics Low

Suspicious activity indicating a potential abuse of a cloud-native email service

A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Attacker's goals:

Adversaries may use cloud-based email services to send phishing or spread malware, abusing legitimate email domains.

Investigative actions:

Check if the identity intended to preform these actions or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

Test period:
3 Hours
Deduplication:
1 Day
2 variations:
  • Suspicious activity indicating a potential abuse of a cloud-native email service involving discovery, weaponization, and impact High (parent: Low)
  • Suspicious activity indicating a potential abuse of a cloud-native email service involving discovery and weaponization Medium (parent: Low)