For the complete documentation index, see llms.txt. This page is also available as Markdown.

Sensitive Exchange mail sent to external users

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

Office 365 Audit

Detection Modules

Identity Threat Module, SaaS Threat Detection, Email

Detector Tags

O365 DLP Analytics

ATT&CK Tactic

Collection (TA0009), Exfiltration (TA0010)

ATT&CK Technique

Email Collection (T1114), Exfiltration Over Alternative Protocol (T1048)

Severity

Informational

Description

A user sent sensitive email messages to external users.

Attacker's Goals

An attacker is attempting to collect sensitive email information.

Investigative actions

  • Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity).

  • Follow further actions done by the account.

  • Look for unusual email patterns from the affected mailbox (e.g. unusual email contents).

  • Examine the user's email activity history for suspicious behavior.

Variations

Exchange mail to external account matching high severity DLP rules

Synopsis

Field
Value

ATT&CK Tactic

Collection (TA0009), Exfiltration (TA0010)

ATT&CK Technique

Email Collection (T1114), Exfiltration Over Alternative Protocol (T1048)

Severity

Low

Description

A user sent sensitive email messages to external users.

Attacker's Goals

An attacker is attempting to collect sensitive email information.

Investigative actions

  • Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity).

  • Follow further actions done by the account.

  • Look for unusual email patterns from the affected mailbox (e.g. unusual email contents).

  • Examine the user's email activity history for suspicious behavior.

Sensitive Exchange mail sent to an external user

Synopsis

Field
Value

ATT&CK Tactic

Collection (TA0009), Exfiltration (TA0010)

ATT&CK Technique

Email Collection (T1114), Exfiltration Over Alternative Protocol (T1048)

Severity

Low

Description

A user sent sensitive email messages to external users.

Attacker's Goals

An attacker is attempting to collect sensitive email information.

Investigative actions

  • Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity).

  • Follow further actions done by the account.

  • Look for unusual email patterns from the affected mailbox (e.g. unusual email contents).

  • Examine the user's email activity history for suspicious behavior.

Was this helpful?