logo

What Did the Attacker Read? MailItemAccessed Tells You

ID: 9dd05d4d-4fe4-5f1e-889b-55430ef1ce23

STIX ID: report--9dd05d4d-4fe4-5f1e-889b-55430ef1ce23

Feed Name: NVISO Labs

Date Published: 2025-10-02

Date Updated: 2026-04-28

Author: Kilian Neumair

...
...

This blog post explains how to investigate Business Email Compromise in Microsoft 365 by ensuring Unified Audit Logging is enabled, exporting Unified Audit Log data, and analyzing MailItemsAccessed events to understand what emails were accessed. It provides KQL-driven methods to detect throttling, identify and interpret sync vs. bind access, pivot on user-agent, session, IP, and geolocation to separate malicious from legitimate activity, and enumerate accessed emails via InternetMessageId for cross-referencing with message traces. The article concludes with recommended response actions (session revocation, password resets, MFA enforcement, rule/OAuth persistence checks) and preventive measures such as rate limiting and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.