ThreatBeaconXThreatBeaconXSubscribe
Microsoft Sentinelv1.0

Detect Multiple Inbound Emails from Brave Alias Senders

Detects potential phishing activity involving Brave Alias (@bravealias.com) email addresses by identifying multiple inbound emails from first-time contacts that were successfully delivered within a one-hour window. Repeated communication from the same Brave Alias may indicate phishing, impersonation, or malicious email campaigns targeting users.

By ThreatBeaconX TH Team · Updated Sep 2, 2026 · 6 views
detect-multiple-inbound-emails-from-brave-alias-senders.kql
EmailEvents
| where Timestamp > ago(1h)
| where EmailDirection == "Inbound"
| extend SenderEmail = iff(
SenderMailFromAddress has "@bravealias.com",
SenderMailFromAddress,
SenderFromAddress
)
| where SenderEmail has "@bravealias.com"
| where IsFirstContact == "1"
| where LatestDeliveryAction == "Delivered"
| summarize MailCount = count() by SenderEmail
| where MailCount >= 3

MITRE ATT&CK Mapping

T1566.002 – Phishing: Spearphishing LinkT1585.002 – Establish Accounts: Email Accounts

False Positives

Legitimate bulk or repeated emails from trusted external senders using Brave Alias (@bravealias.com) addresses, including newsletters, business communications, notifications, or previously approved contacts, may trigger this detection.