Abnormal Security - High-risk email attack detected

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies email attacks detected by Abnormal Security whose attack type maps to a high-risk category (credential phishing, Business Email Compromise, invoice/payment fraud, malware, extortion, sensitive-data phishing, internal account-takeover attacks, or scams). Lower-risk categories such as Spam, Graymail, and Reconnaissance are intentionally excluded. Use this to triage targeted email threats that reached a mailbox.

Attribute Value
Type Analytic Rule
Solution AbnormalSecurity
ID 8effd19a-abab-433a-9184-ae67ac51e6d0
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1566
Required Connectors AbnormalSecurityPush
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
ABNORMAL_SECURITY_THREAT_LOG_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to AbnormalSecurity