Rules : Mimecast - SPAM Message from IP
Mimecast detected an email message with an elevated SPAM score.
Detail
Value
Type
Match
Category
Collection
Apply Risk to Entities
srcDevice_ip, user_username, device_hostname, device_ip
Signal Name
Mimecast - SPAM Message from IP
Summary Expression
Message with elevated spam score from: {{email_sender}}
Score/Severity
Static: 1
Enabled by Default
True
Prototype
False
Tags
_mitreAttackTactic:TA0001, _mitreAttackTactic:TA0009, _mitreAttackTactic:TA0043, _mitreAttackTechnique:T1566, _mitreAttackTechnique:T1566.001, _mitreAttackTechnique:T1566.002, _mitreAttackTechnique:T1598, _mitreAttackTechnique:T1598.002, _mitreAttackTechnique:T1598.003
Origin
Field
Normalized Schema
device_hostname
Normalized Schema
device_ip
Direct from Record
fields['SpamScore']
Normalized Schema
metadata_deviceEventId
Normalized Schema
metadata_product
Normalized Schema
metadata_vendor
Normalized Schema
srcDevice_ip
Normalized Schema
user_email
Normalized Schema
user_username