Browse Rules

Search and filter across all detection sources

78 rules

sagan medium other

[MSAPI-SECURITYCOMPLIANCECENTER] User Restricted From Sending Email

[MSAPI-SECURITYCOMPLIANCECENTER] User Restricted From Sending Email

sentinel high kql

Mimecast Secure Email Gateway - Internal Email Protect

Detects threats from internal email threat protection

sentinel high kql

Mimecast Secure Email Gateway - Internal Email Protect

'Detects threats from internal email threat protection.'

sagan medium other

[Barracuda] Email Gateway Security_Awareness_Training Event Detected

[Barracuda] Email Gateway Security_Awareness_Training Event Detected

sentinel medium kql

TI Map Email entity to SecurityEvent

'Identifies a match in SecurityEvent table from any Email IOC from TI'

sentinel medium kql

TI map Email entity to SecurityEvent

'Identifies a match in SecurityEvent table from any Email IOC from TI'

sentinel informational kql

Mimecast Secure Email Gateway - AV

Detects threats from email anti virus scan

sentinel informational kql

Mimecast Secure Email Gateway - AV

'Detects threats from email anti virus scan.'

sagan medium other

[MSAPI-SECURITYCOMPLIANCECENTER] Alert Entity Generated for Email sending limit exceeded

[MSAPI-SECURITYCOMPLIANCECENTER] Alert Entity Generated for Email sending limit exceeded

anvilogic high spl

Auth0: Email Notification Failure [splunk-auth0]

Threat actors may disrupt security notifications, password resets, or user communications by causing email delivery failures, either through misconfiguration or targeted attacks. This use case detects failed attempts to send email notifications, which could indicate email service issues, unauthorized changes to email settings, or attempts to suppress security alerts.

sentinel medium kql

TI Map Email entity to SecurityAlert

'Identifies a match in SecurityAlert table from any Email IOC from TI which will extend coverage to datatypes such as MCAS, StorageThreatProtection and many others'

sentinel medium kql

TI map Email entity to SecurityAlert

'Identifies a match in SecurityAlert table from any Email IOC from TI which will extend coverage to datatypes such as MCAS, StorageThreatProtection and many others'

sentinel high kql

Mimecast Secure Email Gateway - URL Protect

Detect threat when potentially malicious url found

sentinel high kql

Mimecast Secure Email Gateway - URL Protect

'Detect threat when potentially malicious url found.'

elastic high kql

Threat Intel Email Indicator Match

This rule is triggered when an email indicator from the Threat Intel Filebeat module or integrations matches an event containing email-related data, such as logs from email security gateways or email service providers.

sentinel informational kql

Mimecast Secure Email Gateway - Virus

Detect threat for virus from mail receipt virus event

sentinel informational kql

Mimecast Secure Email Gateway - Virus

'Detect threat for virus from mail receipt virus event.'

sentinel high kql

Mimecast Secure Email Gateway - Impersonation Protect

Detects threats from impersonation mail under targeted threat protection

sentinel high kql

Mimecast Secure Email Gateway - Impersonation Protect

'Detects threats from impersonation mail under targeted threat protection.'

sentinel low kql

Mimecast Secure Email Gateway - Spam Event Thread

Detects threat from spam event thread protection logs

sentinel low kql

Mimecast Secure Email Gateway - Spam Event Thread

'Detects threat from spam event thread protection logs.'

sentinel high kql

Abnormal Security - High-risk email attack detected

'Identifies email attacks detected by Abnormal Security whose attack type maps to a high-risk category (credential phishing, Business Email Compromise, invoice/payment fraud, malware, extortion, sensitive-data phishing, internal account-takeover attacks, or scams). Lower-risk categories such as Spam, Graymail, and Reconnaissance are intentionally excluded. Use this to triage targeted email threats that reached a mailbox.'

sentinel high kql

Mimecast Secure Email Gateway - Attachment Protect

Detect threat for mail attachment under the targeted threat protection

sentinel high kql

Mimecast Secure Email Gateway - Attachment Protect

'Detect threat for mail attachment under the targeted threat protection.'

splunk unknown spl

O365 Email Access By Security Administrator

The following analytic identifies when a user with sufficient access to O365 Security & Compliance portal uses premium investigation features (Threat Explorer) to directly view email. Adversaries may exploit privileged access with this premium feature to enumerate or exfiltrate sensitive data.