Cloud coverage: Detecting an email payroll diversion attack
Threat Detection Report: Midyear Update Read our latest analysis of security tends and the rise of identity-based threats. Contact Us How can we help you? Whether it’s in the cloud or on prem, there’s an abundance of useful Exchange telemetry that defenders can use to detect suspicious email activity like payroll diversion schemes. Email inboxes contain a treasure trove of valuable information and email addresses are among the most critical identifiers in the corporate world. Wresting control of a victim’s inbox not only offers an adversary access to untold amounts of sensitive information but also the ability to impersonate legit user accounts and carry out a multitude of other malicious activities. Therefore, it’s no surprise that adversaries commonly target email systems and that defenders prioritize securing them. Whether it’s hosted locally or (as is more-than-likely) in the cloud, email accounts are practically endpoints that require hardening and layered defense mechanisms. As
Cloud coverage: Detecting an email payroll diversion attack Skip Navigation Get a Demo Products Managed Detection and Response AI Agents Threat Intelligence Automation Security Data Lake Managed Phishing Response Training & Tabletops What's New Plans Solutions By domain Identity Email Endpoint Cloud By technology Zscaler Microsoft CrowdStrike SentinelOne Palo Alto Networks AWS Google Linux & Kubernetes By Industry Financial Services Healthcare Technology Manufacturing Education Government Resources Blog Guides & Overviews Case Studies Videos Webinars Cybersecurity 101 Events Documentation Demo
Explore this link on the map →saved by
related reading
- Exposing and shutting down an inbox heist in actionredcanary.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Malicious Usage of eM Client In Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Email Compromise To Mass Phishing Campaigndarktrace.com
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- Shifting detection left for more effective threat detectionpushsecurity.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com