Skip to content
Threat Feed

Product

Office 365

23 briefs RSS
high advisory

O365 BEC Email Hiding Rule Creation

This analytic detects the creation of suspicious mailbox rules in Office 365, a common technique used in Business Email Compromise (BEC) to hide emails by identifying rules with short or nonsensical names, marking emails as read, or moving them to specific folders.

Office 365 +4 bec o365 email mailboxrule splunk threat-hunting
2r 1t
high advisory

O365 Admin Consent Bypassed by Service Principal

A service principal in Office 365 Azure Active Directory assigns app roles without standard admin consent, potentially bypassing critical administrative controls and leading to unauthorized access or privilege escalation.

Office 365 +1 azuread office365 serviceprincipal adminconsent persistence
2r 2t
high advisory

O365 Security Compliance Alerting for Potential Ransomware Activity

This brief focuses on detecting potential ransomware activity within Microsoft Office 365 environments by monitoring security and compliance alerts, aiding in early identification and mitigation of ransomware threats.

Office 365 +2 ransomware o365 cloud
3r 3t
medium advisory

Detection of User-Reported Phishing or Malware in Office 365

This detection identifies potentially malicious emails reported by users within an Office 365 environment through Security & Compliance policies, indicating possible phishing or malware attacks targeting the organization.

Office 365 +2 office365 phishing user-reporting
2r 1t
medium advisory

Office 365 User Restricted from Sending Email

An Office 365 user account is restricted from sending email, potentially indicating account compromise, policy violation, or administrative action following suspicious activity.

Office 365 o365 email account-compromise
2r 1t
high advisory

O365 Advanced Audit Disabled

Detection of O365 advanced audit being disabled for a specific user, potentially allowing attackers to operate with reduced risk of detection, leading to unauthorized data access, data exfiltration, or account compromise.

Office 365 +3 cloud o365 audit defense-evasion persistence
2r 1t
high advisory

Detection of Malicious Office 365 Inbox Rule Creation

This brief outlines the detection of malicious Office 365 inbox rule creation, where attackers leverage 'New-InboxRule' and 'Set-InboxRule' operations to forward, delete, or obfuscate emails, potentially leading to data exfiltration or business email compromise.

Office 365 o365 inbox-rule email data-exfiltration business-email-compromise
3r 2t
medium advisory

Office 365 MFA Notification Email Deletion for Defense Evasion

Attackers may delete multi-factor authentication (MFA) notification emails in Office 365 to evade detection and maintain unauthorized access after compromising an account.

Office 365 o365 mfa defense_evasion email
2r 1t
high advisory

Office 365 MFA Bypass via Trusted IP Modification

An adversary modifies the trusted IP list in Office 365 to bypass multi-factor authentication (MFA) and gain unauthorized access to accounts.

Office 365 azure o365 mfa bypass defense-evasion
2r 1t
high advisory

Office 365 Concurrent Sessions Indicate Adversary-in-the-Middle (AiTM) Attack

An adversary may compromise user credentials and conduct an Adversary-in-the-Middle (AiTM) attack, granting them unauthorized access to an Office 365 account from multiple IP addresses simultaneously, potentially leading to data theft, account takeover, and internal phishing campaigns.

Office 365 o365 aitm phishing credential-access
2r 1t
high threat

O365 Service Principal Creation Detection

Detection of new service principal creation in O365 tenants, which can be abused by attackers for unauthorized access, API interaction, and data compromise.

Office 365 +5 NOBELIUM Group cloud o365 service_principal persistence azuread
2r 1t
high advisory

O365 Security Feature Modification

Attackers modify or disable Office 365 advanced security settings, such as AntiPhish, SafeLink, SafeAttachment, or Malware policies, to evade detection and operate with reduced risk within the target tenant.

Office 365 +3 o365 email_security defense_evasion persistence
2r 1t
high advisory

O365 Email Receive and Hard Delete Takeover Behavior

Compromised Office 365 accounts may receive and then hard delete emails related to password resets or banking/payroll changes, potentially indicating an attempt to redirect victim payroll to an attacker-controlled bank account.

Office 365 office365 account-takeover email data-destruction
2r 3t
medium advisory

O365 Email Access By Security Administrator

Atypical access to O365 mailboxes is detected when a security administrator uses Threat Explorer features to directly view email, potentially indicating reconnaissance or data exfiltration by a compromised or malicious insider.

Office 365 cloud o365 data exfiltration azure ad
2r 2t
high advisory

O365 Elevated Mailbox Permission Assignment

Detection of elevated mailbox permissions (FullAccess, ChangePermission, ChangeOwner) being assigned in Office 365, potentially leading to unauthorized access, data exfiltration, or privilege escalation.

Office 365 +1 o365 mailbox-permissions privilege-escalation
2r 1t
medium advisory

O365 Compliance Content Search Activity Detected

Detection of content search initiation within the Office 365 Security and Compliance Center using the SearchCreated operation, which may signal unauthorized access to sensitive organizational data such as emails and documents, potentially leading to data exfiltration and compliance breaches.

Microsoft 365 +1 o365 compliance content search data exfiltration
2r 1t
high advisory

O365 BEC Email Hiding Rule Creation

This analytic detects suspicious Office 365 mailbox rule creation, a common technique used in Business Email Compromise (BEC), by scoring rule attributes like short names, marking emails as read, and moving emails to specific folders.

Office 365 +1 bec office365 email
2r 2t
medium threat

O365 Application Registration Owner Added

A new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.

Azure Active Directory +1 NOBELIUM Group azuread o365 persistence
3r 1t
high advisory

O365 Add App Role Assignment Grant User

This analytic detects the addition of an application role assignment grant to a user in Office 365, which can indicate unauthorized privilege escalation or the assignment of sensitive roles, leading to unauthorized access within the Office 365 environment.

Office 365 +1 office365 azuread privilege-escalation
2r 1t
high advisory

High Number of Failed Office 365 Logins from Single Source

The analytic detects multiple failed login attempts in Office365 Azure Active Directory from a single source IP address, potentially indicating brute-force or password spraying attacks.

Office 365 +1 cloud office365 credential-access password-spraying
1r 1t
high advisory

O365 Email Password and Payroll Compromise

Attackers compromise O365 accounts and delete emails related to password resets and payroll changes, potentially redirecting payroll to attacker-controlled accounts.

Office 365 account-compromise office365 payroll-fraud data-destruction
2r 3t
high advisory

O365 Email Account Compromise via Excessive Hard Deletes

Compromised O365 accounts may perform excessive email hard deletes within an hour to remove evidence of malicious activity, potentially indicating account takeover.

Office 365 o365 email account_compromise data_destruction
1r 2t
high advisory

O365 MFA Disabled by User

Detection of Multi-Factor Authentication (MFA) being disabled for a user account in Office 365, potentially indicating malicious activity or an insider threat.

Office 365 o365 mfa persistence
2r 1t