Email contains URL delivering high-risk file type
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour 30 Minutes
Required Data
Microsoft 365 Emails
Detection Modules
Detector Tags
Malicious URLs
ATT&CK Tactic
Execution (TA0002), Credential Access (TA0006)
ATT&CK Technique
User Execution (T1204), Brute Force: Password Cracking (T1110.002)
Severity
Informational
Description
Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery.
Attacker's Goals
To bypass attachment-based blocking by delivering malware or exploiting payloads via URLs pointing to file types commonly blocked by email vendors.
Investigative actions
Review the URLs and determine if they host executable or script-based content.
Check threat intelligence sources for reputation or known associations with malware.
Investigate whether any users clicked the URL or downloaded the file.
Analyze the file content using sandbox or static analysis tools.
Variations
Was this helpful?
