Unusual file-sharing links for mailbox owner
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour 30 Minutes
Required Data
Microsoft 365 Emails
Detection Modules
Detector Tags
Malicious URLs
ATT&CK Tactic
Initial Access (TA0001), Execution (TA0002)
ATT&CK Technique
Phishing: Spearphishing Link (T1566.002), User Execution: Malicious File (T1204.002)
Severity
Informational
Description
The email contains unusual file-sharing link(s) for mailbox owner.
Attacker's Goals
Deliver malware or exfiltrate data via auto-download file-sharing links.
Investigative actions
Analyze the linked file(s) to determine if they pose any security risk.
Check the sender's communication history within the organization.
Analyze the file reputation using sandbox or threat intelligence sources.
Verify whether similar links were sent to other users.
Variations
Was this helpful?
