Email with file-sharing link containing auto-download parameter
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour 30 Minutes
Required Data
Microsoft 365 Emails
Detection Modules
Detector Tags
Malicious URLs
ATT&CK Tactic
Initial Access (TA0001), Execution (TA0002)
ATT&CK Technique
Phishing: Spearphishing Link (T1566.002), User Execution: Malicious File (T1204.002)
Severity
Low
Description
The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download.
Attacker's Goals
The attacker may be attempting to deliver malware or exfiltrate data using auto-download file-sharing links.
Investigative actions
Analyze the linked file(s) to determine if they pose any security risk.
Check the sender's communication history within the organization.
Analyze the file reputation using sandbox or threat intelligence sources.
Verify whether similar links were sent to other users.
Variations
Was this helpful?
