Suspicious Email - UBA Anomaly

Description

This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by Splunk User Behavior Analytics (UBA).

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Security Monitoring

Category

Adversary Tactics

Alert Volume

This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by Splunk User Behavior Analytics (UBA).

SPL Difficulty

None

Journey

Stage 1

MITRE ATT&CK Tactics

Initial Access

MITRE ATT&CK Techniques

Phishing

Phishing

MITRE Threat Groups

Dragonfly
GOLD SOUTHFIELD

   Help

Suspicious Email - UBA Anomaly Help

You must be ingesting data from email logs and have Splunk integrated with UBA. This anomaly is raised by a UBA detection model called "SuspiciousEmailDetectionModel." Ensure that this model is enabled on your UBA instance.

   Search

Open in Search