Microsoft Sentinelv1.0
Detect Multiple Inbound Emails from Brave Alias Senders
Detects potential phishing activity involving Brave Alias (@bravealias.com) email addresses by identifying multiple inbound emails from first-time contacts that were successfully delivered within a one-hour window. Repeated communication from the same Brave Alias may indicate phishing, impersonation, or malicious email campaigns targeting users.
By ThreatBeaconX TH Team · Updated Sep 2, 2026 · 6 views
detect-multiple-inbound-emails-from-brave-alias-senders.kql
EmailEvents| where Timestamp > ago(1h)| where EmailDirection == "Inbound"| extend SenderEmail = iff(SenderMailFromAddress has "@bravealias.com",SenderMailFromAddress,SenderFromAddress)| where SenderEmail has "@bravealias.com"| where IsFirstContact == "1"| where LatestDeliveryAction == "Delivered"| summarize MailCount = count() by SenderEmail| where MailCount >= 3
MITRE ATT&CK Mapping
T1566.002 – Phishing: Spearphishing LinkT1585.002 – Establish Accounts: Email Accounts
False Positives
Legitimate bulk or repeated emails from trusted external senders using Brave Alias (@bravealias.com) addresses, including newsletters, business communications, notifications, or previously approved contacts, may trigger this detection.