BEC Example: A Fictional Microsoft 365 Incident Walkthrough
A fictional AiTM business email compromise rebuilt from its Microsoft 365 logs: spray, token replay, inbox rules, forwarding, OAuth consent, fake invoice.
This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.
A fictional AiTM business email compromise rebuilt from its Microsoft 365 logs: spray, token replay, inbox rules, forwarding, OAuth consent, fake invoice.
How AiTM phishing steals Microsoft 365 sessions despite MFA, and how to detect the token replay in Entra ID sign-in logs and the Unified Audit Log.