Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com/ |
| Categories | domains |
| Version | 3.0.10 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2023-08-04 |
| Solution Folder | Business Email Compromise - Financial Fraud |
| Marketplace | Azure Marketplace · Popularity: ⚪ Very Low (0%) |
| Pre-requisites | Microsoft Entra ID, Microsoft 365, Amazon Web Services, Microsoft Defender XDR, Okta Single Sign-On |
Business Email Compromise (BEC) attacks often aim to commit financial fraud by locating sensitive payment or invoice details and using these to hijack legitimate transactions. This solution, in combination with other solutions listed below, provide a range of content to help detect and investigate BEC attacks at different stages of the attack cycle, and across multiple data sources including AWS, SAP, Okta, Dynamics 365, Microsoft Entra ID, Microsoft 365 and network logs.
This content covers all stages of the attack chain from an initial phishing attack vector, establishing persistence to an environment, locating and collecting sensitive financial information from data stores, and then perpetrating and hiding their fraud. This range of content complements the coverage Microsoft Defender XDR provides across Microsoft Defender products.
In order to gain the most comprehensive coverage possible customers should deploy the content included in this solution as well as content from the following solutions:
Microsoft Entra ID solution for Sentinel
Microsoft 365 solution for Sentinel
Amazon Web Services
Microsoft Defender XDR
Okta Single Sign On
This solution depends on 5 other solution(s):
| Solution |
|---|
| Amazon Web Services |
| Microsoft 365 |
| Microsoft Defender XDR |
| Microsoft Entra ID |
| Okta Single Sign-On |
This solution does not include its own data connectors but uses connectors from dependency solutions:
This solution queries 6 table(s) from its content items:
| Table | Used By Content |
|---|---|
AWSCloudTrail |
Analytics |
AuditLogs |
Analytics, Hunting |
AwsBucketAPILogs_CL |
Hunting |
EmailEvents |
Hunting |
OfficeActivity |
Analytics, Hunting |
SigninLogs |
Hunting |
The following 2 table(s) are used internally by this solution's content items:
| Table | Used By Content |
|---|---|
BehaviorAnalytics |
Hunting |
IdentityInfo |
Analytics, Hunting |
This solution includes 20 content item(s):
| Content Type | Count |
|---|---|
| Hunting Queries | 13 |
| Analytic Rules | 7 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Account Elevated to New Role | Medium | Persistence | AuditLogs |
| Authentication Method Changed for Privileged Account | High | Persistence | AuditLogsInternal use: IdentityInfo |
| Malicious BEC Inbox Rule | Medium | Persistence, DefenseEvasion | OfficeActivity |
| Privileged Account Permissions Changed | Medium | PrivilegeEscalation | AuditLogsInternal use: IdentityInfo |
| Suspicious access of BEC related documents | Medium | Collection | - |
| Suspicious access of BEC related documents in AWS S3 buckets | Medium | Collection | AWSCloudTrail |
| User Added to Admin Role | Low | PrivilegeEscalation | AuditLogs |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.10 | 10-11-2025 | Update in Analytical Rule alert description |
| 3.0.9 | 05-06-2024 | Analytical Rule description updated |
| 3.0.8 | 04-04-2024 | Updated Entity Mappings |
| 3.0.7 | 28-02-2024 | Removed usage of BlastRadius from Hunting Queries |
| 3.0.6 | 16-02-2024 | Updated the solution to fix Analytic Rules deployment issue |
| 3.0.5 | 08-02-2024 | Tagged for dependent solutions for deployment |
| 3.0.4 | 10-01-2024 | Updated Analytic Rule (AuthenticationMethodChangedforPrivilegedAccount.yaml) |
| 3.0.3 | 23-11-2023 | Updated description of Hunting query |
| 3.0.2 | 06-11-2023 | Changes for rebranding from Microsoft 365 Defender to Microsoft Defender XDR |
| 3.0.1 | 03-11-2023 | Updated Analytic Rule datatype and descriptions for Hunting queries |
| 3.0.0 | 07-08-2023 | Initial Solution Release |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊