BEC Example: A Fictional Microsoft 365 Incident Walkthrough
A fictional AiTM business email compromise rebuilt from its Microsoft 365 logs: spray, token replay, inbox rules, forwarding, OAuth consent, fake invoice.
This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.
A fictional AiTM business email compromise rebuilt from its Microsoft 365 logs: spray, token replay, inbox rules, forwarding, OAuth consent, fake invoice.
How attackers use inbox rules and forwarding in a BEC, how to find them in the Unified Audit Log and with Get-InboxRule, and how to tell them from real ones.