logo

How to hunt & defend against Business Email Compromise (BEC)

ID: 862bc6bd-5e3f-531f-8388-f9232d3e3824

STIX ID: report--862bc6bd-5e3f-531f-8388-f9232d3e3824

Feed Name: NVISO Labs

Date Published: 2025-03-21

Date Updated: 2026-04-28

Author: Thomas Papaloukas

...
...

This report provides a hands-on threat-hunting methodology for Business Email Compromise (BEC) in Microsoft 365/Entra, including KQL queries to baseline and detect anomalous sign-ins (e.g., unexpected geolocations, untrusted devices, user-agent mirroring), scoping with suspicious IPs (including VPN ranges), and investigation of post-compromise activities such as MFA/security info changes and inbox rule manipulation. It also recommends mitigations—enforcing MFA, applying Conditional Access Policies, and conducting phishing awareness—to reduce the attack surface and prevent successful BEC attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.