What Did the Attacker Read? MailItemAccessed Tells You
ID: 9dd05d4d-4fe4-5f1e-889b-55430ef1ce23
STIX ID: report--9dd05d4d-4fe4-5f1e-889b-55430ef1ce23
Feed Name: NVISO Labs
This blog post explains how to investigate Business Email Compromise in Microsoft 365 by ensuring Unified Audit Logging is enabled, exporting Unified Audit Log data, and analyzing MailItemsAccessed events to understand what emails were accessed. It provides KQL-driven methods to detect throttling, identify and interpret sync vs. bind access, pivot on user-agent, session, IP, and geolocation to separate malicious from legitimate activity, and enumerate accessed emails via InternetMessageId for cross-referencing with message traces. The article concludes with recommended response actions (session revocation, password resets, MFA enforcement, rule/OAuth persistence checks) and preventive measures such as rate limiting and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
