Mimecast
Telemetry Evidence
These values show how indexed rules identify Mimecast telemetry.Kusto
MimecastAudit MimecastAudit_CL MimecastCG MimecastDLP MimecastDLP_CL MimecastSIEM_CL MimecastTTPAttachment MimecastTTPAttachment_CL MimecastTTPImpersonation MimecastTTPImpersonation_CL MimecastTTPUrl MimecastTTPUrl_CL
Detection Rules
Kusto #
- Mimecast Audit - Logon Authentication Failed source high: Detects threat when logon authentication failure found in audit
T1110 - Mimecast Audit - Logon Authentication Failed source high: Detects threat when logon authentication failure found in audit
T1110 - Mimecast Data Leak Prevention - Hold source informational: Detects threat for data leak when action is hold
T1030 - Mimecast Data Leak Prevention - Hold source informational: Detects threat for data leak when action is hold
T1030 - Mimecast Data Leak Prevention - Notifications source high: Detects threat for data leak when action is notification
T1030 - Mimecast Data Leak Prevention - Notifications source high: Detects threat for data leak when action is notification
T1030 - Mimecast Secure Email Gateway - Attachment Protect source high: 'Detect threat for mail attachment under the targeted threat protection.'
T0865,T1114,T1566 - Mimecast Secure Email Gateway - Attachment Protect source high: Detect threat for mail attachment under the targeted threat protection
T0865,T1114,T1566 - Mimecast Secure Email Gateway - AV source informational: 'Detects threats from email anti virus scan.'
T1053 - Mimecast Secure Email Gateway - AV source informational: Detects threats from email anti virus scan
T1053
Show 13 more
- Mimecast Secure Email Gateway - Impersonation Protect source high: 'Detects threats from impersonation mail under targeted threat protection.'
T1114 - Mimecast Secure Email Gateway - Impersonation Protect source high: Detects threats from impersonation mail under targeted threat protection
T1114 - Mimecast Secure Email Gateway - Internal Email Protect source high: 'Detects threats from internal email threat protection.'
T1534,T1546 - Mimecast Secure Email Gateway - Internal Email Protect source high: Detects threats from internal email threat protection
T1534,T1546 - Mimecast Secure Email Gateway - Spam Event Thread source low: 'Detects threat from spam event thread protection logs.'
T1083 - Mimecast Secure Email Gateway - Spam Event Thread source low: Detects threat from spam event thread protection logs
T1083 - Mimecast Secure Email Gateway - URL Protect source high: 'Detect threat when potentially malicious url found.'
T1566 - Mimecast Secure Email Gateway - URL Protect source high: Detect threat when potentially malicious url found
T1566 - Mimecast Secure Email Gateway - Virus source informational: 'Detect threat for virus from mail receipt virus event.'
T1053 - Mimecast Secure Email Gateway - Virus source informational: Detect threat for virus from mail receipt virus event
T1053 - Mimecast Targeted Threat Protection - Attachment Protect source high: 'Detects a threat for an unsafe attachment in an email.'
T0865 - Mimecast Targeted Threat Protection - Impersonation Protect source high: 'Detects a maliciously tagged impersonation.'
T1114 - Mimecast Targeted Threat Protection - URL Protect source high: 'Detects malicious scan results and actions which are not allowed.'
T0865
Other Index Content
This content is indexed for research but excluded from the detection-rule headline.Kusto #
T0865T1114T0865