EMAIL BETA - Email containing a redirected link

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2025-04-07
Category
Analytics Alert Reference
Index by
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Days

Required Data

  • Requires:
    • Office 365 Mail

Detection Modules

Email

Detector Tags

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

An email with a redirected link has been detected.

Attacker's Goals

Attackers can use link redirection to disguise malicious URLs.

Investigative actions

  • Carefully analyze the full redirection chain. Be cautious with this process, as clicking on links can pose security risks.
  • Use URL reputation services to check if the final destination or any of the intermediate URLs are known to be malicious or associated with phishing.
  • If the message contains attachments/links, scrutinize them for any suspicious indications.
  • Monitor further actions taken, such as file downloads or access to potentially malicious links.

Variations

EMAIL BETA - Email containing a redirected link with multiple redirections

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

An email with a redirected link has been detected.
The email contains at least one redirected link with multiple redirection patterns, which is concerning as it can obscure malicious URLs and evade security filters.

Attacker's Goals

Attackers can use link redirection to disguise malicious URLs.

Investigative actions

  • Carefully analyze the full redirection chain. Be cautious with this process, as clicking on links can pose security risks.
  • Use URL reputation services to check if the final destination or any of the intermediate URLs are known to be malicious or associated with phishing.
  • If the message contains attachments/links, scrutinize them for any suspicious indications.
  • Monitor further actions taken, such as file downloads or access to potentially malicious links.