Email containing a redirected link
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Microsoft 365 Emails
Detection Modules
Detector Tags
Malicious URLs
ATT&CK Tactic
Stealth (TA0005), Execution (TA0002)
ATT&CK Technique
Hide Artifacts (T1564), User Execution (T1204)
Severity
Informational
Description
An email with a redirected link has been detected.
Attacker's Goals
Attackers can use link redirection to disguise malicious URLs.
Investigative actions
Carefully analyze the full redirection chain. Be cautious with this process, as clicking on links can pose security risks.
Use URL reputation services to check if the final destination or any of the intermediate URLs are known to be malicious or associated with phishing.
If the message contains attachments or links, scrutinize them for any suspicious indications.
Monitor further actions taken, such as file downloads or access to potentially malicious links.
Variations
Was this helpful?
