Microsoft 365 Exchange junk email settings modified by a suspicious VPN
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when the Exchange junk email settings have been modified by a suspicious VPN.
Strategy
Monitor Microsoft 365 Exchange audit logs to look for the operation Set-MailboxJunkEmailConfiguration
. Attackers who have gained unauthorized access to a victim’s account may modify junk email settings to redirect incoming emails. This technique could be used by an attacker to avoid detections focussing on email inbox rules.
Triage and response
- Identify any additional unusual behaviors:
- Previous failed logins.
- Unexpected VPN usage.
- Unusual user agent.
- Contact the user
{{@usr.email}}
to determine if they made the change to the junk email configuration. - If
{{@usr.email}}
is not aware of the activity:- Investigate other activities performed by the user
{{@usr.email}}
using the Cloud SIEM - User Investigation dashboard. - Begin your organization’s incident response process and investigate.