Unusual display name in From header
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Microsoft 365 Emails
Detection Modules
ATT&CK Tactic
Reconnaissance (TA0043), Initial Access (TA0001)
ATT&CK Technique
Phishing for Information (T1598), Phishing (T1566)
Severity
Informational
Description
An email was detected with an unusual display name in the From header.
Attacker's Goals
Evade defenses and hide potential malicious data inside the email display name.
Investigative actions
Analyze the email further to determine the source of the anomaly and what can be done about it.
Variations
PreviousUnusual DB process spawning a shell
NextUnusual Encrypting File System Remote call (EFSRPC) to domain controller
Was this helpful?
