flâneur — a map of the web's best reading

Common Oauth Apps Used in Business Email Compromise – Syne's Cyber Corner

cybercorner.tech · 1,568 words · saved by 1 readers

This article serves as another place to document some common (and not so common) Oauth applications that are abused for malicious purposes during a BEC. Some are well documented, while others are rarer, only discussed between responders or detailed on GitHub lists. The places where some of these apps are detailed may only provide a brief summary of the application, while this article aims to provide more information on the potential use and impact of those less common applications. For more details on the apps such as their App ID and MITRE details, check out the below two links. https://github.com/randomaccess3/detections/blob/main/M365_Oauth_Apps/MaliciousOauthAppDetections.json https://huntresslabs.github.io/rogueapps (Click an application to go directly to it’s entry.) This is one of the most documented and abused applications. In a tenant the application will show up as PERFECTDATA SOFTWARE, but the real software behind it is called Email Backup Wizard. It is a desktop application

Posted in Azure AD Forensics Incident Response Office 365 Posted by By syne0 August 29, 2024 No Comments This article serves as another place to document some common (and not so common) Oauth applications that are abused for malicious purposes during a BEC. Some are well documented, while others are rarer, only discussed between responders or detailed on GitHub lists. The places where some of these apps are detailed may only provide a brief summary of the application, while this article aims to provide more information on the potential use and impact of those less common applications. For more

Explore this link on the map →

saved by

related reading