How to hunt & defend against Business Email Compromise (BEC)
ID: 862bc6bd-5e3f-531f-8388-f9232d3e3824
STIX ID: report--862bc6bd-5e3f-531f-8388-f9232d3e3824
Feed Name: NVISO Labs
This report provides a hands-on threat-hunting methodology for Business Email Compromise (BEC) in Microsoft 365/Entra, including KQL queries to baseline and detect anomalous sign-ins (e.g., unexpected geolocations, untrusted devices, user-agent mirroring), scoping with suspicious IPs (including VPN ranges), and investigation of post-compromise activities such as MFA/security info changes and inbox rule manipulation. It also recommends mitigations—enforcing MFA, applying Conditional Access Policies, and conducting phishing awareness—to reduce the attack surface and prevent successful BEC attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
