Email with malicious attachment opened by user

This rule is part of a beta feature. To learn more, contact Support.
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when an email with a malicious attachment is opened.

Strategy

This rule monitors Abnormal logs to detect when a malicious file is opened by a user.

Triage and response

  1. Investigate the user, {{@messages.toAddresses}}, who was impacted by the email.
  2. If confirmed as a threat, implement measures to block or limit the impact of the suspicious activity.
  3. Follow company procedures for handling malicious files, including isolating the endpoint, running antivirus/antimalware scans, analyzing logs, and updating security policies.