What We Saw in 90 days from 4 Million Microsoft Office 365 Accounts by Vectra AI Security Research team
ID: e6fb4cc0-9647-5cc3-bccb-a0a386b8ae09
STIX ID: report--e6fb4cc0-9647-5cc3-bccb-a0a386b8ae09
Feed Name: Vectra AI Blog
Vectra’s 2020 Spotlight Report on Microsoft Office 365 analyzes attacker activity across more than 4 million accounts (June–August 2020), finding widespread lateral movement (96% of customers), suspicious Power Automate use (71%), and eDiscovery abuse (56%). The report explains how native Office 365 services can be weaponized for command-and-control and data exfiltration, and how federation can be leveraged to bypass MFA, illustrated by case studies of business email compromise and phishing. It emphasizes rapid detection of SaaS privilege misuse and highlights how NDR capabilities can prioritize, investigate, and disrupt these behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
