Exposing and shutting down an inbox heist in action
Threat Detection Report: Midyear Update Read our latest analysis of security tends and the rise of identity-based threats. Contact Us How can we help you? Here’s what we discovered while responding to and investigating a compromised email account. One day in January 2023, Red Canary detected the creation of a suspicious email rule in one of our customer’s Microsoft 365 environments. After a thorough investigation, we worked with the customer to better understand what had happened (post-credential compromise) and how to resolve it. We hope the following article helps you better understand how to detect, investigate, and respond to suspicious email activity. A time-saving hack to organize and filter mailboxes automatically, email rules exist to make our lives easier. Ask most executives, engineers, or anyone else that receives hundreds of emails a day for that matter, and they’ll likely jump at the opportunity to provide their pro tips on how best to utilize this feature. But every lig
Exposing and shutting down an inbox heist in action Skip Navigation Get a Demo Products Managed Detection and Response AI Agents Threat Intelligence Automation Security Data Lake Managed Phishing Response Training & Tabletops What's New Plans Solutions By domain Identity Email Endpoint Cloud By technology Zscaler Microsoft CrowdStrike SentinelOne Palo Alto Networks AWS Google Linux & Kubernetes By Industry Financial Services Healthcare Technology Manufacturing Education Government Resources Blog Guides & Overviews Case Studies Videos Webinars Cybersecurity 101 Events Documentation Demo Video H
Explore this link on the map →saved by
related reading
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Malicious Usage of eM Client In Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Shifting detection left for more effective threat detectionpushsecurity.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com