Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
N/A (single event) |
Deduplication Period |
1 Day |
Required Data |
|
Detection Modules |
|
Detector Tags |
|
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
External email with mailbox owner hidden in BCC as the only internal recipient.
Attacker's Goals
BCC enables sending the same email to multiple hidden recipients without revealing them to each other.
Investigative actions
- Review the headers and content for patterns or anomalies.
- Assess the email's context and attack techniques to determine the potential risk.
- Investigate if similar patterns have occurred recently across the organization.