For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cloud email service activity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Requires one of the following data sources: AWS Audit Log OR Azure Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Internal Spearphishing (T1534)

Severity

Informational

Description

A cloud Identity performed an email service operation.

Attacker's Goals

Abuse the cloud email service for sending phishing emails.

Investigative actions

  • Check for any following actions related to this activity.

  • Verify that the identity did not abuse the email service to send phishing emails to victims.

Variations

Unusual cloud email service activity

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Internal Spearphishing (T1534)

Severity

Low

Description

A cloud Identity performed an email service operation for the first time in the tenant.

Attacker's Goals

Abuse the cloud email service for sending phishing emails.

Investigative actions

  • Check for any following actions related to this activity.

  • Verify that the identity did not abuse the email service to send phishing emails to victims.

Cloud email service entity creation

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Internal Spearphishing (T1534)

Severity

Low

Description

A cloud Identity created a new cloud email identity.

Attacker's Goals

Abuse the cloud email service for sending phishing emails.

Investigative actions

  • Check for any following actions related to this activity.

  • Verify that the identity did not abuse the email service to send phishing emails to victims.

Was this helpful?