Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
31 detectors match the current filters. tactic: TA0005 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Email attachment with multiple extensions The email includes an attachment(s) with two extensions. The first one being an executable extension. This may indicate an attempt at masquerading the true file type through the misuse of multiple extensions in the attachment name. | Informational | Email Security | Microsoft 365 Emails | Execution, Defense Evasion |
| Analytics BIOC | Email attachment with Right-to-Left Override Unicode character The email message contains an attachment with a hidden Right-to-Left Override Unicode character. | Low | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email attachment(s) with potentially malicious MIME type The email message contains an attachment(s) with a potentially malicious MIME type. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email containing a link with an IP address convention was detected A link with IP address convention was detected within the email body. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email containing a redirected link An email with a redirected link has been detected. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email with URL shortener detected A URL shortener was detected in the email body. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Exchange anti-phish policy disabled or removed A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange audit log disabled A user disabled the Exchange audit log. This may indicate an attempt to evade detection. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange DKIM signing configuration disabled A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange email-hiding inbox rule A user configured an Exchange inbox rule that may be used to hide emails. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange email-hiding transport rule A user configured an Exchange transport rule that may be used to hide emails in the organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange mailbox audit bypass A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange malware filter policy removed A user removed an Exchange malware filter policy, which may prevent the detection of malware. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange Safe Attachment policy disabled or removed A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange Safe Link policy disabled or removed A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | External email display name impersonation of internal personnel Potential email attempting to impersonate an internal user has been detected. The sender's email address appears unusual in relation to the provided display name, suggesting a possible impersonation attempt targeting an internal user. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Potential spoofing of internal domain spotted An external sender is possibly impersonating an employee by spoofing the company's internal address. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion |
| Analytics BIOC | Punycode characters detected in URL(s) Punycode character(s) detected within URL(s) in email content. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Suspicious brand affiliation detected The sender's name or address suggests association with a recognized brand, but the email address doesn't match established patterns for that brand. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Suspicious DKIM Result The email contains a suspicious DKIM entry, showing either an unexpected verification result (none, fail, or policy) or a mismatched signing domain, which may indicate potential tampering or spoofing activity. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Suspicious DMARC result The email has a suspicious DMARC result of either fail or none, which may indicate a potential domain misconfiguration or spoofing. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Suspicious SPF Result The email has a suspicious SPF result of fail, soft fail, or policy, which may indicate a potential domain misconfiguration or spoofing. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Suspicious Unicode character detected in email Unicode characters can be used for obfuscation, allowing malicious actors to disguise harmful intent, URLs or attachments By embedding non-printing Unicode characters, attackers can bypass security filters and evade detection mechanisms Such characters may also be used for phishing attempts that appear legitimate to both users and security systems. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Unusual hostname for the sending mail server in the email headers The detected mail server hostname had not been observed in the organization's emails in the past 30 days. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Unusual sender IP subnet This IP address has not been observed in correlation with the sender's fully qualified domain name within the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Usage of homograph characters detected in an email Detected characters resembling Latin letters within an email's subject and/or body. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Usage of homograph characters detected in an email's from header Detected characters resembling Latin letters within an email's From header. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics | User moved Exchange sent messages to deleted items A user moved sent messages to deleted items in Exchange. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Well-known brand in sender headers with header inconsistencies Sender headers include a well-known brand with header inconsistencies indicating possible impersonation. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | X-Forefront-Antispam-Report has flagged this email as a potential threat This email has been categorized by X-Forefront-Antispam-Report as a threat, suggesting it is likely malicious in nature (e.g., spam, phishing, impersonation, etc.). | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion, Execution |