Mailbox Client Access Setting (CAS) changed

Cortex XDR Analytics Alert Reference by data source

Last date published
2024-04-15
Order
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires one of the following data sources:
    • Windows Event Collector
      OR
    • XDR Agent
  • Requires:
    • eXtended Threat Hunting (XTH)

Detection Modules

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Data Staged: Local Data Staging (T1074.001)

Severity

Medium

Description

An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data.

Attacker's Goals

Gain access to the data in the compromised mailbox.

Investigative actions

  • Examine the PowerShell command to identify which mailbox's access setting has been modified.
  • verify that the change in the client access setting was executed by a trusted source.