EMAIL BETA - Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values

Cortex XDR Analytics Alert Reference by Alert name

Product
Cortex XDR
Last date published
2025-04-21
Category
Analytics Alert Reference
Index by
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Days

Required Data

  • Requires:
    • Microsoft 365 Emails

Detection Modules

Email

Detector Tags

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam.

Attacker's Goals

Achieve financial gain, distribute malware, or phish for sensitive information through mass unsolicited emails.

Investigative actions

  • Examine email headers to trace origins and check for signs of spoofing.
  • Analyze the email content for spam indicators like suspicious links and aggressive marketing language.
  • Monitor further actions taken, such as file downloads or access to potentially malicious links.

Variations

EMAIL BETA - Email with high Spam Confidence Level and Bulk Complaint Level values

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam.

Attacker's Goals

Achieve financial gain, distribute malware, or phish for sensitive information through mass unsolicited emails.

Investigative actions

  • Examine email headers to trace origins and check for signs of spoofing.
  • Analyze the email content for spam indicators like suspicious links and aggressive marketing language.
  • Monitor further actions taken, such as file downloads or access to potentially malicious links.


EMAIL BETA - Email with high Spam Confidence Level or Bulk Complaint Level values

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam.

Attacker's Goals

Achieve financial gain, distribute malware, or phish for sensitive information through mass unsolicited emails.

Investigative actions

  • Examine email headers to trace origins and check for signs of spoofing.
  • Analyze the email content for spam indicators like suspicious links and aggressive marketing language.
  • Monitor further actions taken, such as file downloads or access to potentially malicious links.


EMAIL BETA - Email with medium Spam Confidence Level and Bulk Complaint Level values

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam.

Attacker's Goals

Achieve financial gain, distribute malware, or phish for sensitive information through mass unsolicited emails.

Investigative actions

  • Examine email headers to trace origins and check for signs of spoofing.
  • Analyze the email content for spam indicators like suspicious links and aggressive marketing language.
  • Monitor further actions taken, such as file downloads or access to potentially malicious links.


EMAIL BETA - Email with medium Spam Confidence Level or Bulk Complaint Level values

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam.

Attacker's Goals

Achieve financial gain, distribute malware, or phish for sensitive information through mass unsolicited emails.

Investigative actions

  • Examine email headers to trace origins and check for signs of spoofing.
  • Analyze the email content for spam indicators like suspicious links and aggressive marketing language.
  • Monitor further actions taken, such as file downloads or access to potentially malicious links.