UBA : MaaS360 malicious email received

The QRadar® User Behavior Analytics (UBA) app supports use cases based on rules for certain behavioral anomalies.

UBA : MaaS360 malicious email received

Enabled by default

False

Default senseValue

5

Description

Detects MaaS360 event indicating a user received a malicious email.

Required configuration

IBM MaaS360 Security DSM and events.

Support rule

BB:UBA : Common Event Filters

Log source types

IBM MaaS360 Security ((Event ID: MALICIOUS_EMAIL with Event Category : THREAT)