For the complete documentation index, see llms.txt. This page is also available as Markdown.

Sudden spike in outbound email volume

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

2 Hours

Required Data

Microsoft 365 Emails

Detection Modules

Email

ATT&CK Tactic

Execution (TA0002), Credential Access (TA0006)

ATT&CK Technique

User Execution (T1204), Brute Force: Password Cracking (T1110.002)

Severity

Informational

Description

Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe.

Attacker's Goals

  • Extracting valuable information outside the company.

  • Bypass Data Loss Prevention (DLP) by splitting data across multiple emails.

Investigative actions

  • Check the content of the email that was sent.

  • Review the external recipient address and assess its reputation.

  • Review past emails sent from this mailbox for any suspicious activity.

  • Check for unusual emails sent to this recipient's address.

  • Monitor further action taken, such as accessing to private keys, API tokens and sensitive data.

Variations

Sudden spike in outbound emails sent to external recipients

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Credential Access (TA0006)

ATT&CK Technique

User Execution (T1204), Brute Force: Password Cracking (T1110.002)

Severity

Informational

Description

Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe.

Attacker's Goals

  • Extracting valuable information outside the company.

  • Bypass Data Loss Prevention (DLP) by splitting data across multiple emails.

Investigative actions

  • Check the content of the email that was sent.

  • Review the external recipient address and assess its reputation.

  • Review past emails sent from this mailbox for any suspicious activity.

  • Check for unusual emails sent to this recipient's address.

  • Monitor further action taken, such as accessing to private keys, API tokens and sensitive data.

Sudden spike in outbound emails sent to internal recipients

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Credential Access (TA0006)

ATT&CK Technique

User Execution (T1204), Brute Force: Password Cracking (T1110.002)

Severity

Informational

Description

Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe.

Attacker's Goals

  • Extracting valuable information outside the company.

  • Bypass Data Loss Prevention (DLP) by splitting data across multiple emails.

Investigative actions

  • Check the content of the email that was sent.

  • Review the external recipient address and assess its reputation.

  • Review past emails sent from this mailbox for any suspicious activity.

  • Check for unusual emails sent to this recipient's address.

  • Monitor further action taken, such as accessing to private keys, API tokens and sensitive data.

Was this helpful?