Red Sift - New email with URL from previously unseen source

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects email forensics events that contain one or more URLs where the sender is using a source IP address not seen in the previous 14 days, which may indicate suspicious infrastructure changes or phishing activity.

Attribute Value
Type Analytic Rule
Solution Red Sift
ID 6084dfd8-830b-4839-9a9c-5f08cc984729
Severity Medium
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1566
Required Connectors RedSiftPush
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
RedSiftEmailForensics_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Red Sift