Unusual attachment volume in outbound emails
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Hour
Required Data
Microsoft 365 Emails
Detection Modules
Detector Tags
Exfiltration
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Exfiltration Over Alternative Protocol (T1048)
Severity
Informational
Description
Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe.
Attacker's Goals
Extracting valuable information outside the company.
Bypass Data Loss Prevention (DLP) by splitting data across multiple emails.
Investigative actions
Check the content of the email that was sent.
Review the external recipient address and assess its reputation.
Review past emails sent from this mailbox for any suspicious activity.
Check for unusual emails sent to this recipient's address.
Monitor further action taken, such as accessing to private keys, API tokens and sensitive data.
Variations
Was this helpful?
