> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-mail-items-accessed-from-multiple-ips-in-the-same-subnet.md).

# User mail items accessed from multiple IPs in the same subnet

### Synopsis

| Field                | Value                                                                                     |
| -------------------- | ----------------------------------------------------------------------------------------- |
| Activation Period    | 14 Days                                                                                   |
| Training Period      | 30 Days                                                                                   |
| Test Period          | 1 Hour                                                                                    |
| Deduplication Period | 1 Day                                                                                     |
| Required Data        | Office 365 Audit                                                                          |
| Detection Modules    | Identity Threat Module                                                                    |
| Detector Tags        | Extortion                                                                                 |
| ATT\&CK Tactic       | Collection (TA0009), Command and Control (TA0011)                                         |
| ATT\&CK Technique    | Email Collection: Remote Email Collection (T1114.002), Proxy: Multi-hop Proxy (T1090.003) |
| Severity             | Informational                                                                             |

### Description

A user's Exchange mailbox was accessed from multiple distinct caller IPs that all reside in the same /16 subnet within a short time window. This pattern is characteristic of VPS abuse and IP rotation designed to evade per-IP velocity controls.

### Attacker's Goals

An adversary may access user mail items from multiple IP addresses within the same subnet, which can aid in evading per-IP rate limits and avoiding detection while maintaining persistent access to a compromised mailbox.

### Investigative actions

* Enumerate every caller IP in the subnet that accessed the user's mailbox in the past 24h and check their SPUR/threat-intel reputation.
* Inspect the user's sessions: look for new OAuth grants, new inbox rules, MFA changes and revoke active sessions.
* Correlate the subnet/ASN with other tenant users to determine the scope.

### Variations

<details>

<summary>User mail items accessed from rotating IPs in same subnet with anomalous properties</summary>

**Synopsis**

| Field             | Value                                                                                     |
| ----------------- | ----------------------------------------------------------------------------------------- |
| ATT\&CK Tactic    | Collection (TA0009), Command and Control (TA0011)                                         |
| ATT\&CK Technique | Email Collection: Remote Email Collection (T1114.002), Proxy: Multi-hop Proxy (T1090.003) |
| Severity          | Low                                                                                       |

**Description**

A user's mailbox was accessed from multiple rotating IPs in the same /16 subnet, and at least one IP address contributed additional anomaly signals (e.g., unmanaged or risky caller IP, anomalous country or ASN for this user).

**Attacker's Goals**

An adversary may access user mail items from multiple IP addresses within the same subnet, which can aid in evading per-IP rate limits and avoiding detection while maintaining persistent access to a compromised mailbox.

**Investigative actions**

* Enumerate every caller IP in the subnet that accessed the user's mailbox in the past 24h and check their SPUR/threat-intel reputation.
* Inspect the user's sessions: look for new OAuth grants, new inbox rules, MFA changes and revoke active sessions.
* Correlate the subnet/ASN with other tenant users to determine the scope.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/user-mail-items-accessed-from-multiple-ips-in-the-same-subnet.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
