MALWARE:_Content_Replaced_Office 365_Exchange

Alert

MALWARE: Content Replaced

SK4 unified event:
Connector/Service

Office 365/Exchange

SK4 Version:

2.3.105

Created Date:

Tue Jan 22 2019 09:11:55 GMT+0000 (Coordinated Universal Time)

Last Update:

Tue May 14 2019 07:03:23 GMT+0000 (Coordinated Universal Time)

Category

Security Alert

Description

A message detected as MALWARE has been received by email.

Search query

cef_vendor="skyformation" cef_name="security-threat-detected" destinationServiceName="Office 365" sourceServiceName="Exchange" fileType="file" act="send-mail"

Parsed CEF
Unparsed raw data

Expand to see an example...

Audit sources