Files
splunk-security_content/stories/suspicious_emails.yml
Patrick Bareiss 7cbc9a9ba6 WIP
2020-04-30 10:34:18 +02:00

33 lines
1.4 KiB
YAML

name: Suspicious Emails
id: 2b1800dd-92f9-47ec-a981-fdf1351e5d55
version: 1
date: '2020-01-27'
description: Email remains one of the primary means for attackers to gain an initial
foothold within the modern enterprise. Detect and investigate suspicious emails
in your environment with the help of the searches in this Analytic Story.
narrative: 'It is a common practice for attackers of all types to leverage targeted
spearphishing campaigns and mass mailers to deliver weaponized email messages and
attachments. Fortunately, there are a number of ways to monitor email data in Splunk
to detect suspicious content.\
Once a phishing message has been detected, the next steps are to answer the following
questions: \
1. Which users have received this or a similar message in the past?\
1. When did the targeted campaign begin?\
1. Have any users interacted with the content of the messages (by downloading an
attachment or clicking on a malicious URL)?This Analytic Story provides detection
searches to identify suspicious emails, as well as contextual and investigative
searches to help answer some of these questions.'
author: Bhavin Patel, Splunk
type: ESCU
references:
- https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/
tags:
analytics_story: Suspicious Emails
usecase: Advanced Threat Detection
category:
- Adversary Tactics