Observations From Business Email Compromise (BEC) Attacks
ID: 6c82e03e-c5d8-579c-abaf-f925a1af7baf
STIX ID: report--6c82e03e-c5d8-579c-abaf-f925a1af7baf
Feed Name: TrustedSec blog
Threat Score
This article provides investigative guidance for business email compromise (BEC) incidents, stressing the importance of log analysis, message-header and IOC extraction, inspection of mailbox inbox rules (and automated enumeration via PowerShell) to find message redirection/persistent collection, and review of MFA and OAuth registrations to detect bypass or persistence; it aims to help reduce attacker dwell time and improve detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
