Exchange malware filter policy removed
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection, Email
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685)
Severity
Low
Description
A user removed an Exchange malware filter policy, which may prevent the detection of malware.
Attacker's Goals
An attacker is attempting to evade detection.
Investigative actions
Follow further actions done by the account.
Verify that the configuration change was expected.
Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Investigate if any other security policies have been changed or removed.
Monitor for signs of malware in future messages.
Was this helpful?
