Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

78 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Display text URL differs from actual URL An email contains a hyperlink whose display text shows a URL different from the actual destination URL. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Email attachment with a potentially malicious file extension The email message includes attachments with file types that are typically blocked by the email vendor as a precaution due to their suspicious nature. Informational Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Email attachment with multiple extensions The email includes an attachment(s) with two extensions. The first one being an executable extension. This may indicate an attempt at masquerading the true file type through the misuse of multiple extensions in the attachment name. Informational Email Security Microsoft 365 Emails Execution, Defense Evasion
Analytics BIOC Email attachment with Right-to-Left Override Unicode character The email message contains an attachment with a hidden Right-to-Left Override Unicode character. Low Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email attachment(s) with potentially malicious MIME type The email message contains an attachment(s) with a potentially malicious MIME type. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email containing a link with an IP address convention was detected A link with IP address convention was detected within the email body. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email containing a redirected link An email with a redirected link has been detected. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email contains URL delivering high-risk file type Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email mimics replies or forwards without an actual ongoing conversation An email with a subject line or body that includes signs of a reply or forward without an actual ongoing conversation. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Email sent using an automated system or script detected The message contains X-PHP-Script or X-PHP-Originating-Script headers, indicating it was generated by an automated PHP script or web application. While often legitimate, this behavior is frequently associated with shared hosting abuse, phishing kits, and compromised web applications. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Email was received from an unknown address using a public provider domain The email was received from an unknown address, that was seen for the first time in the organization in the past month, and registered under a public provider. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email was received from an unknown sender using a disposable domain The email was received from an unknown sender using a disposable email provider, first seen in the organization in the past month. Low Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email with file-sharing link containing auto-download parameter The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download. Low Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Email with URL shortener detected A URL shortener was detected in the email body. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Exchange anti-phish policy disabled or removed A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange audit log disabled A user disabled the Exchange audit log. This may indicate an attempt to evade detection. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange compliance search created A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Exchange DKIM signing configuration disabled A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange email-hiding inbox rule A user configured an Exchange inbox rule that may be used to hide emails. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange email-hiding transport rule A user configured an Exchange transport rule that may be used to hide emails in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange mailbox audit bypass A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics Exchange mailbox delegation permissions added A user added delegation permissions to an Exchange mailbox. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Exchange malware filter policy removed A user removed an Exchange malware filter policy, which may prevent the detection of malware. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange Safe Attachment policy disabled or removed A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange Safe Link policy disabled or removed A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange transport forwarding rule configured A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange user mailbox forwarding A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC External email display name impersonation of internal personnel Potential email attempting to impersonate an internal user has been detected. The sender's email address appears unusual in relation to the provided display name, suggesting a possible impersonation attempt targeting an internal user. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC External email with a single internal recipient hidden in BCC External email with mailbox owner hidden in BCC as the only internal recipient. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC First-seen email from mailbox owner to external recipient's address in the last 30 days Internal sender initiated first-time communication with an external recipient in the last 30 days. Informational Email Security Microsoft 365 Emails Exfiltration
Analytics BIOC First-time attachment exchange Detects when an attachment is sent between individuals for the first time in 30 days. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Initial person-to-person email contact Identifies when a sender initiates contact with individuals with no prior history of interaction in the last 30 days. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics BIOC Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Moniker link detected in URL(s) A Moniker link was detected within the email's body. The link has the convention of a Moniker link (CVE-2024-21413) correlated to a suspicious URL scheme. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Near-empty email from an external sender The email was sent from an external sender and contains minimal content. Near-empty emails from external sources are uncommon and may be used to bypass content-based detection or prompt user interaction without clear context. Informational Email Security Microsoft 365 Emails Reconnaissance
Analytics Numerous emails sent by a single sender to multiple internal recipients Numerous emails were sent to multiple internal recipients. This may indicate spam or any other malicious attempt. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Outbound email contains file-sharing service link sent to external recipient Identifies outbound emails that include links to file-sharing services sent externally. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email includes an external BCC recipient observed for the first time Internal sender BCC'd an external recipient whose address has not been observed in prior communications. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email to an address hosted by a public email service provider Internal sender emailed to an address hosted by a public email service provider. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. Medium Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Initial Access
Analytics BIOC Potential spoofing of internal domain spotted An external sender is possibly impersonating an employee by spoofing the company's internal address. Informational Email Security Microsoft 365 Emails Initial Access, Defense Evasion
Analytics BIOC Punycode characters detected in URL(s) Punycode character(s) detected within URL(s) in email content. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Quarantined email released to recipients This message was previously quarantined by vendor and has now been released and delivered to the intended recipients. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Rare DLP rule match by user A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Rarely seen sender address in the organization An email was received from a sender that has not been observed in the organization in the last 30 days. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Rarely seen sender domain in the organization An email was received from a domain that has not been observed in the organization in the last 30 days. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC SAAS - Email was reported by the user or administrator as a phishing attempt An email reported by the user or administrator as a phishing attempt has been detected. Informational Email Security Office 365 Audit Collection
Analytics BIOC Sending unusual file(s) to an external address Unusual files sent to an external address. Low Email Security Microsoft 365 Emails Initial Access, Exfiltration
Analytics Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics Sudden spike in outbound email volume Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Suspicious brand affiliation detected The sender's name or address suggests association with a recognized brand, but the email address doesn't match established patterns for that brand. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Suspicious DKIM Result The email contains a suspicious DKIM entry, showing either an unexpected verification result (none, fail, or policy) or a mismatched signing domain, which may indicate potential tampering or spoofing activity. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Suspicious DMARC result The email has a suspicious DMARC result of either fail or none, which may indicate a potential domain misconfiguration or spoofing. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics Suspicious sender exhibiting automated sending patterns Multiple messages from a single sender were observed over a short period, all having the same subject and differing body content. This repetitive pattern may indicate automated or scripted behavior. Informational Email Security Microsoft 365 Emails Initial Access
Analytics Suspicious sending domain with sender address randomization Multiple messages from a single sender domain were observed over a short period, each using a unique sender address. This per-message sender randomization is uncommon for legitimate senders and suggests automated behavior. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Suspicious SPF Result The email has a suspicious SPF result of fail, soft fail, or policy, which may indicate a potential domain misconfiguration or spoofing. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics Suspicious theme and sentiment in email The email's body has a theme and sentiment that may indicate a malicious attempt. Informational Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Impact
Analytics BIOC Suspicious Unicode character detected in email Unicode characters can be used for obfuscation, allowing malicious actors to disguise harmful intent, URLs or attachments By embedding non-printing Unicode characters, attackers can bypass security filters and evade detection mechanisms Such characters may also be used for phishing attempts that appear legitimate to both users and security systems. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Training simulation email detected This email was flagged as part of a training simulation. Low Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Uncommon URL domain(s) in your organization detected in email We have identified unpopular domain(s) in URL(s) within this email. Informational Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Unrecognized internal address (AAD mismatch) An email was received from an address using an internal domain, but the sender is not found in Active Directory. This may indicate an impersonation attempt or domain spoofing. Informational Email Security Microsoft 365 Emails Initial Access
Analytics Unusual attachment volume in outbound emails Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe. Informational Email Security Microsoft 365 Emails Exfiltration
Analytics BIOC Unusual display name in From header An email was detected with an unusual display name in the From header. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Unusual file-sharing links for mailbox owner The email contains unusual file-sharing link(s) for mailbox owner. Informational Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Unusual hostname for the sending mail server in the email headers The detected mail server hostname had not been observed in the organization's emails in the past 30 days. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Unusual sender IP subnet This IP address has not been observed in correlation with the sender's fully qualified domain name within the last 30 days. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Unusual URL(s) sent by a brand were observed in the email A URL that is not usually associated with the brand has been detected. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Usage of homograph characters detected in an email Detected characters resembling Latin letters within an email's subject and/or body. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Usage of homograph characters detected in an email attachment(s) name Detected characters resembling Latin letters within an email attachment(s) name. This method could be used as a method to evade text or file scanners and analyzers. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Usage of homograph characters detected in an email's from header Detected characters resembling Latin letters within an email's From header. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics User moved Exchange sent messages to deleted items A user moved sent messages to deleted items in Exchange. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Well-known brand in sender headers with header inconsistencies Sender headers include a well-known brand with header inconsistencies indicating possible impersonation. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC X-Forefront-Antispam-Report has flagged this email as a potential threat This email has been categorized by X-Forefront-Antispam-Report as a threat, suggesting it is likely malicious in nature (e.g., spam, phishing, impersonation, etc.). Informational Email Security Microsoft 365 Emails Initial Access, Defense Evasion, Execution