mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
33 lines
1.4 KiB
YAML
33 lines
1.4 KiB
YAML
name: Suspicious Emails
|
|
id: 2b1800dd-92f9-47ec-a981-fdf1351e5d55
|
|
version: 1
|
|
date: '2020-01-27'
|
|
description: Email remains one of the primary means for attackers to gain an initial
|
|
foothold within the modern enterprise. Detect and investigate suspicious emails
|
|
in your environment with the help of the searches in this Analytic Story.
|
|
narrative: 'It is a common practice for attackers of all types to leverage targeted
|
|
spearphishing campaigns and mass mailers to deliver weaponized email messages and
|
|
attachments. Fortunately, there are a number of ways to monitor email data in Splunk
|
|
to detect suspicious content.\
|
|
|
|
Once a phishing message has been detected, the next steps are to answer the following
|
|
questions: \
|
|
|
|
1. Which users have received this or a similar message in the past?\
|
|
|
|
1. When did the targeted campaign begin?\
|
|
|
|
1. Have any users interacted with the content of the messages (by downloading an
|
|
attachment or clicking on a malicious URL)?This Analytic Story provides detection
|
|
searches to identify suspicious emails, as well as contextual and investigative
|
|
searches to help answer some of these questions.'
|
|
author: Bhavin Patel, Splunk
|
|
type: ESCU
|
|
references:
|
|
- https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/
|
|
tags:
|
|
analytics_story: Suspicious Emails
|
|
usecase: Advanced Threat Detection
|
|
category:
|
|
- Adversary Tactics
|