Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. technique: T1110 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Email contains URL delivering high-risk file type Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC External email with a single internal recipient hidden in BCC External email with mailbox owner hidden in BCC as the only internal recipient. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC First-time attachment exchange Detects when an attachment is sent between individuals for the first time in 30 days. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Initial person-to-person email contact Identifies when a sender initiates contact with individuals with no prior history of interaction in the last 30 days. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Moniker link detected in URL(s) A Moniker link was detected within the email's body. The link has the convention of a Moniker link (CVE-2024-21413) correlated to a suspicious URL scheme. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email contains file-sharing service link sent to external recipient Identifies outbound emails that include links to file-sharing services sent externally. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email includes an external BCC recipient observed for the first time Internal sender BCC'd an external recipient whose address has not been observed in prior communications. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email to an address hosted by a public email service provider Internal sender emailed to an address hosted by a public email service provider. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Sudden spike in outbound email volume Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Unusual URL(s) sent by a brand were observed in the email A URL that is not usually associated with the brand has been detected. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Usage of homograph characters detected in an email attachment(s) name Detected characters resembling Latin letters within an email attachment(s) name. This method could be used as a method to evade text or file scanners and analyzers. Informational Email Security Microsoft 365 Emails Execution, Credential Access