Threat Hunting for Business Email Compromise Through User Agents
ID: c1f08d0b-8ea5-5469-b457-fb7d97cdd58b
STIX ID: report--c1f08d0b-8ea5-5469-b457-fb7d97cdd58b
Feed Name: Huntress Blog
The report details a threat-hunting approach to detect potential business email compromise in Microsoft 365 by flagging successful logins using the uncommon azsdk-python/AZURECLI user agent, correlating anomalies in geography and behavior to confirm malicious access (85 total hits, four successful in June 2023). It provides actionable detection guidance (event.action:UserLoggedIn AND user_agent.original.text:"azsdk-python"), maps activity to ATT&CK T1078.004 (valid cloud accounts), lists IoCs (213.154.80.21, 203.251.62.51, 91.158.221.9, 118.98.90.2), and advises applying MFA and conditional access to mitigate BEC risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
