sentinel
high
kql
Abnormal Security - High-risk email attack detected
'Identifies email attacks detected by Abnormal Security whose attack type maps to a
high-risk category (credential phishing, Business Email Compromise, invoice/payment
fraud, malware, extortion, sensitive-data phishing, internal account-takeover attacks,
or scams). Lower-risk categories such as Spam, Graymail, and Reconnaissance are
intentionally excluded. Use this to triage targeted email threats that reached a mailbox.'