Email attachment(s) with potentially malicious MIME type
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Microsoft 365 Emails
Detection Modules
ATT&CK Tactic
Stealth (TA0005), Execution (TA0002)
ATT&CK Technique
Masquerading: Masquerade File Type (T1036.008), User Execution (T1204)
Severity
Informational
Description
The email message contains an attachment(s) with a potentially malicious MIME type.
Attacker's Goals
Bypass security filters and deliver malicious content to users
Deploy malicious attachments through emails to compromise systems, gain unauthorized access, or facilitate cyber threats.
Investigative actions
Carefully analyze attachments for any indications of suspicious or malicious behavior.
Scrutinize the attachments for any suspicious indications.
Confirm whether the attachments were successfully delivered to the recipient's mailbox.
If the attachments were delivered successfully, verify whether the recipient downloaded them.
Variations
Was this helpful?
