logo

Spoofing Microsoft 365 Like It’s 1995

ID: 97cee9e7-5c31-5c30-9d17-aca372feaa94

STIX ID: report--97cee9e7-5c31-5c30-9d17-aca372feaa94

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2022-05-24

Date Updated: 2026-04-27

Author: BHIS

...
...

This report explains how Microsoft 365's Direct Send feature (unauthenticated SMTP via company-com.mail.protection.outlook.com) can be abused to spoof trusted internal/external senders and deliver phishing emails into enterprise inboxes. The author provides PoC PowerShell commands, discusses mail flow and Exchange Online Protection behavior, warns about attachment/attachment-filtering limits and IP banning, and recommends defenders validate mail gateway configurations and trusted sender handling to mitigate this attack path.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.