BEC-ware the Phish (part 3): Detect and Prevent Incidents in M365
ID: 58e61303-1644-50cb-9b5e-09b40b754f0b
STIX ID: report--58e61303-1644-50cb-9b5e-09b40b754f0b
Feed Name: Pen Test Partners Blog
This guide outlines practical steps to harden Microsoft 365 against Business Email Compromise by configuring and tuning Exchange Online Protection and Defender for Office 365 threat and alert policies, using custom mail flow rules, and calibrating Defender for Cloud Apps anomaly detections (e.g., inbox manipulation, forwarding, impossible travel). It advises prioritizing technical controls over user training alone, applying KQL to identify and reduce noisy alerts, and leveraging Sentinel for centralized correlation and incident management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
