Entra ID service principals in business email compromise schemes
Threat Detection Report: Midyear Update Read our latest analysis of security tends and the rise of identity-based threats. Contact Us How can we help you? The service principals in Microsoft’s Entra ID can be a boon for business email compromise, but they’re also a key log source for detection. Adversaries have started to abuse service principals in Microsoft’s Entra ID identity platform. As was openly discussed in CISA’s investigation of the Microsoft key-signing breach and another breach caused by the threat group called Midnight Blizzard, the use of service principals was a key mechanism for reading emails in victim organization mailboxes. After crafting valid tokens with newly obtained stolen signing keys, adversaries were able to read emails from their victims’ mailboxes using an unidentified application. The Microsoft breach was reportedly discovered from a customer’s detection analytic internally dubbed the “Big Yellow Taxi.” While the exact detection logic from “Big Yellow Ta
Entra ID service principals in business email compromise schemes | Red Canary Skip Navigation Get a Demo Products Managed Detection and Response AI Agents Threat Intelligence Automation Security Data Lake Managed Phishing Response Training & Tabletops What's New Plans Solutions By domain Identity Email Endpoint Cloud By technology Zscaler Microsoft CrowdStrike SentinelOne Palo Alto Networks AWS Google Linux & Kubernetes By Industry Financial Services Healthcare Technology Manufacturing Education Government Resources Blog Guides & Overviews Case Studies Videos Webinars Cybersecurity 101 Events
Explore this link on the map →saved by
related reading
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Malicious Usage of eM Client In Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Exposing and shutting down an inbox heist in actionredcanary.com
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Revoke user access in an emergency in Microsoft Entra ID - Microsoft Entra ID | Microsoft Learnlearn.microsoft.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Shifting detection left for more effective threat detectionpushsecurity.com