> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/near-empty-email-from-an-external-sender.md).

# Near-empty email from an external sender

### Synopsis

| Field                | Value                                      |
| -------------------- | ------------------------------------------ |
| Activation Period    | 14 Days                                    |
| Training Period      | 30 Days                                    |
| Test Period          | N/A (single event)                         |
| Deduplication Period | 1 Day                                      |
| Required Data        | Microsoft 365 Emails                       |
| Detection Modules    | Email                                      |
| Detector Tags        | Reconnaissance                             |
| ATT\&CK Tactic       | Reconnaissance (TA0043)                    |
| ATT\&CK Technique    | Gather Victim Identity Information (T1589) |
| Severity             | Informational                              |

### Description

The email was sent from an external sender and contains minimal content. Near-empty emails from external sources are uncommon and may be used to bypass content-based detection or prompt user interaction without clear context.

### Attacker's Goals

Attackers send reconnaissance emails to explore an organization's email security by verifying email address validity and testing spam filter effectiveness. The gathered information enables them to craft more precise and effective attacks, such as phishing or business email compromise (BEC).

### Investigative actions

* Check the content of the body and whether it has any relevance to the recipients.
* Check the email address for any unusual spellings.
* Check the email address for any missing letters.
* Verify the sender's address to confirm its legitimacy.
* Check for previous emails from the sender's address.
* Verify whether the sender's IP address has appeared in different log sources before.

### Variations

<details>

<summary>Blank email with an inline attachment from an external sender</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Reconnaissance (TA0043)                    |
| ATT\&CK Technique | Gather Victim Identity Information (T1589) |
| Severity          | Informational                              |

**Description**

This email was sent from an external sender and contains no readable message content, but includes an inline attachment. Empty emails with embedded content are often used to obscure the intent of the message and may be associated with phishing or malware delivery attempts.

**Attacker's Goals**

Attackers send reconnaissance emails to explore an organization's email security by verifying email address validity and testing spam filter effectiveness. The gathered information enables them to craft more precise and effective attacks, such as phishing or business email compromise (BEC).

**Investigative actions**

* Check the content of the body and whether it has any relevance to the recipients.
* Check the email address for any unusual spellings.
* Check the email address for any missing letters.
* Verify the sender's address to confirm its legitimacy.
* Check for previous emails from the sender's address.
* Verify whether the sender's IP address has appeared in different log sources before.

</details>

<details>

<summary>Blank email with an attachment from an external sender</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Reconnaissance (TA0043)                    |
| ATT\&CK Technique | Gather Victim Identity Information (T1589) |
| Severity          | Informational                              |

**Description**

The email was sent from an external sender and contains no message content while including an attachment. Attachment-only emails from external sources can be used to entice recipients into opening potentially malicious files without contextual information.

**Attacker's Goals**

Attackers send reconnaissance emails to explore an organization's email security by verifying email address validity and testing spam filter effectiveness. The gathered information enables them to craft more precise and effective attacks, such as phishing or business email compromise (BEC).

**Investigative actions**

* Check the content of the body and whether it has any relevance to the recipients.
* Check the email address for any unusual spellings.
* Check the email address for any missing letters.
* Verify the sender's address to confirm its legitimacy.
* Check for previous emails from the sender's address.
* Verify whether the sender's IP address has appeared in different log sources before.

</details>

<details>

<summary>Empty email from an external sender</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Reconnaissance (TA0043)                    |
| ATT\&CK Technique | Gather Victim Identity Information (T1589) |
| Severity          | Informational                              |

**Description**

The email was sent from an external sender and contains no subject or message content. While not always malicious, completely empty emails are unusual and may be part of reconnaissance, delivery testing, or social engineering activity.

**Attacker's Goals**

Attackers send reconnaissance emails to explore an organization's email security by verifying email address validity and testing spam filter effectiveness. The gathered information enables them to craft more precise and effective attacks, such as phishing or business email compromise (BEC).

**Investigative actions**

* Check the content of the body and whether it has any relevance to the recipients.
* Check the email address for any unusual spellings.
* Check the email address for any missing letters.
* Verify the sender's address to confirm its legitimacy.
* Check for previous emails from the sender's address.
* Verify whether the sender's IP address has appeared in different log sources before.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/near-empty-email-from-an-external-sender.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
