Acronis - Multiple Inboxes with Malicious Content Detected
| Id | 5090ad7b-4b47-4cab-9015-bffb43aecde8 |
| Rulename | Acronis - Multiple Inboxes with Malicious Content Detected |
| Description | Many inboxes containing malicious content could indicate a potential ongoing phishing attack. |
| Severity | Medium |
| Tactics | InitialAccess |
| Techniques | T1566.002 T1566.001 |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1d |
| Trigger threshold | 2 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Acronis Cyber Protect Cloud/Analytic Rules/AcronisMultipleInboxesWithMaliciousContentDetected.yaml |
| Version | 1.0.0 |
| Arm template | 5090ad7b-4b47-4cab-9015-bffb43aecde8.json |
CommonSecurityLog
| where DeviceVendor == "Acronis"
| where DeviceEventClassID in
("MaliciousURLDetectedInM365MailboxBackup",
"MalwareDetectedInM365MailboxBackup",
"MaliciousEmailDetectedPerceptionPointWarning")
| summarize MaliciousContent = count() by DeviceName
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Acronis Cyber Protect Cloud/Analytic Rules/AcronisMultipleInboxesWithMaliciousContentDetected.yaml
eventGroupingSettings:
aggregationKind: SingleAlert
queryPeriod: 1d
version: 1.0.0
entityMappings:
- fieldMappings:
- identifier: HostName
columnName: DeviceName
entityType: Host
incidentConfiguration:
groupingConfiguration:
matchingMethod: AnyAlert
reopenClosedIncident: true
enabled: true
lookbackDuration: P1D
createIncident: true
customDetails:
DeviceName: DeviceName
queryFrequency: 1h
triggerOperator: gt
kind: Scheduled
id: 5090ad7b-4b47-4cab-9015-bffb43aecde8
tactics:
- InitialAccess
query: |
CommonSecurityLog
| where DeviceVendor == "Acronis"
| where DeviceEventClassID in
("MaliciousURLDetectedInM365MailboxBackup",
"MalwareDetectedInM365MailboxBackup",
"MaliciousEmailDetectedPerceptionPointWarning")
| summarize MaliciousContent = count() by DeviceName
requiredDataConnectors: []
triggerThreshold: 2
description: Many inboxes containing malicious content could indicate a potential ongoing phishing attack.
name: Acronis - Multiple Inboxes with Malicious Content Detected
severity: Medium
relevantTechniques:
- T1566.002
- T1566.001