For the complete documentation index, see llms.txt. This page is also available as Markdown.

SAAS - Email was reported by the user or administrator as a phishing attempt

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Hour

Required Data

Office 365 Audit

Detection Modules

Email

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Email Collection (T1114)

Severity

Informational

Description

An email reported by the user or administrator as a phishing attempt has been detected.

Attacker's Goals

Trick the user into interacting with a malicious email by disguising it as legitimate, potentially leading to credential theft, malware infection, or data exfiltration.

Investigative actions

  • Analyze the sender's IP address and domain reputation.

  • Check if the sender has appeared in other logs or alerts across the organization.

  • Review any URLs or attachments for signs of phishing, malware, or command-and-control communication.

  • Correlate user actions (e.g., link clicks, file downloads) to assess potential compromise.

  • Determine whether similar emails were sent to other users to identify a broader campaign.

Variations

SAAS - Phishing report with suspicious verdict on internal domain sender

Synopsis

Field
Value

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Email Collection (T1114)

Severity

Low

Description

An email with an internal sender domain was reported as a phishing attempt.This may indicate either a compromised internal account or an external attacker impersonating an internal user.

Attacker's Goals

Trick the user into interacting with a malicious email by disguising it as legitimate, potentially leading to credential theft, malware infection, or data exfiltration.

Investigative actions

  • Analyze the sender's IP address and domain reputation.

  • Check if the sender has appeared in other logs or alerts across the organization.

  • Review any URLs or attachments for signs of phishing, malware, or command-and-control communication.

  • Correlate user actions (e.g., link clicks, file downloads) to assess potential compromise.

  • Determine whether similar emails were sent to other users to identify a broader campaign.

SAAS - Phishing report with with suspicious verdict

Synopsis

Field
Value

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Email Collection (T1114)

Severity

Low

Description

An email with a Malware/Block verdict reported by the user or administrator has been detected.

Attacker's Goals

Trick the user into interacting with a malicious email by disguising it as legitimate, potentially leading to credential theft, malware infection, or data exfiltration.

Investigative actions

  • Analyze the sender's IP address and domain reputation.

  • Check if the sender has appeared in other logs or alerts across the organization.

  • Review any URLs or attachments for signs of phishing, malware, or command-and-control communication.

  • Correlate user actions (e.g., link clicks, file downloads) to assess potential compromise.

  • Determine whether similar emails were sent to other users to identify a broader campaign.

Was this helpful?