Analytics Informational

Unusual attachment volume in outbound emails

Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe.

Module:
Email Security
Licensed by:
Email Security
Data source:
Microsoft 365 Emails
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
Detector tags: Exfiltration
Attacker's goals:

Extracting valuable information outside the company. Bypass Data Loss Prevention (DLP) by splitting data across multiple emails.

Investigative actions:

Check the content of the email that was sent. Review the external recipient address and assess its reputation. Review past emails sent from this mailbox for any suspicious activity. Check for unusual emails sent to this recipient's address. Monitor further action taken, such as accessing to private keys, API tokens and sensitive data.

Test period:
10 Minutes
Deduplication:
1 Hour
2 variations:
  • Unusual attachment volume in outbound emails to a single external recipient Informational
  • Unusual attachment amount and size in outbound emails Informational