Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

7 detectors match the current filters. technique: T1036 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Email attachment with multiple extensions The email includes an attachment(s) with two extensions. The first one being an executable extension. This may indicate an attempt at masquerading the true file type through the misuse of multiple extensions in the attachment name. Informational Email Security Microsoft 365 Emails Execution, Defense Evasion
Analytics BIOC Email attachment(s) with potentially malicious MIME type The email message contains an attachment(s) with a potentially malicious MIME type. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email containing a link with an IP address convention was detected A link with IP address convention was detected within the email body. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Punycode characters detected in URL(s) Punycode character(s) detected within URL(s) in email content. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Suspicious Unicode character detected in email Unicode characters can be used for obfuscation, allowing malicious actors to disguise harmful intent, URLs or attachments By embedding non-printing Unicode characters, attackers can bypass security filters and evade detection mechanisms Such characters may also be used for phishing attempts that appear legitimate to both users and security systems. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Usage of homograph characters detected in an email Detected characters resembling Latin letters within an email's subject and/or body. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Usage of homograph characters detected in an email's from header Detected characters resembling Latin letters within an email's From header. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. Informational Email Security Microsoft 365 Emails Defense Evasion