Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
22 detectors match the current filters. technique: T1204 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Email attachment with a potentially malicious file extension The email message includes attachments with file types that are typically blocked by the email vendor as a precaution due to their suspicious nature. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Email attachment with multiple extensions The email includes an attachment(s) with two extensions. The first one being an executable extension. This may indicate an attempt at masquerading the true file type through the misuse of multiple extensions in the attachment name. | Informational | Email Security | Microsoft 365 Emails | Execution, Defense Evasion |
| Analytics BIOC | Email attachment with Right-to-Left Override Unicode character The email message contains an attachment with a hidden Right-to-Left Override Unicode character. | Low | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email attachment(s) with potentially malicious MIME type The email message contains an attachment(s) with a potentially malicious MIME type. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email containing a link with an IP address convention was detected A link with IP address convention was detected within the email body. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email containing a redirected link An email with a redirected link has been detected. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email contains URL delivering high-risk file type Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Email with file-sharing link containing auto-download parameter The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download. | Low | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | External email with a single internal recipient hidden in BCC External email with mailbox owner hidden in BCC as the only internal recipient. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | First-time attachment exchange Detects when an attachment is sent between individuals for the first time in 30 days. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Initial person-to-person email contact Identifies when a sender initiates contact with individuals with no prior history of interaction in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Moniker link detected in URL(s) A Moniker link was detected within the email's body. The link has the convention of a Moniker link (CVE-2024-21413) correlated to a suspicious URL scheme. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Outbound email contains file-sharing service link sent to external recipient Identifies outbound emails that include links to file-sharing services sent externally. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Outbound email includes an external BCC recipient observed for the first time Internal sender BCC'd an external recipient whose address has not been observed in prior communications. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Outbound email to an address hosted by a public email service provider Internal sender emailed to an address hosted by a public email service provider. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Punycode characters detected in URL(s) Punycode character(s) detected within URL(s) in email content. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics | Sudden spike in outbound email volume Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Uncommon URL domain(s) in your organization detected in email We have identified unpopular domain(s) in URL(s) within this email. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Unusual file-sharing links for mailbox owner The email contains unusual file-sharing link(s) for mailbox owner. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Unusual URL(s) sent by a brand were observed in the email A URL that is not usually associated with the brand has been detected. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Usage of homograph characters detected in an email attachment(s) name Detected characters resembling Latin letters within an email attachment(s) name. This method could be used as a method to evade text or file scanners and analyzers. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | X-Forefront-Antispam-Report has flagged this email as a potential threat This email has been categorized by X-Forefront-Antispam-Report as a threat, suggesting it is likely malicious in nature (e.g., spam, phishing, impersonation, etc.). | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion, Execution |