Vendor: Microsoft

June 14, 2023 · View on GitHub

Product: Exchange

Use-Case: Phishing

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
11111
Event TypeRulesModels
dlp-email-alert-outT1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
EM-OD-A: Abnormal email domain for organization
EM-OD: Domains per organization