Analytics
Low
✕
Suspicious activity indicating a potential abuse of a cloud-native email service
A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Attacker's goals:
Adversaries may use cloud-based email services to send phishing or spread malware, abusing legitimate email domains.
Investigative actions:
Check if the identity intended to preform these actions or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
- Test period:
- 3 Hours
- Deduplication:
- 1 Day
2 variations:
- Suspicious activity indicating a potential abuse of a cloud-native email service involving discovery, weaponization, and impact High (parent: Low)
- Suspicious activity indicating a potential abuse of a cloud-native email service involving discovery and weaponization Medium (parent: Low)