Microsoft 365 Anomalous Amount of Deleted Emails

microsoft-365

Classification:

attack

Tactic:

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Goal

Detect when an anomalous amount of emails are deleted from Microsoft 365 Exchange.

Strategy

Monitor Microsoft 365 Exchange audit logs to look for events with an @evt.name value of HardDelete, where the @Folder.Path is the inbox (*Inbox*).

Triage and response

  1. Determine if the user {{@usr.id}} intended to delete the observed emails.
  2. If {{@usr.id}} is not responsible for the email deletions, investigate {{@usr.id}} for anomalous activity. If necessary, initiate your company’s incident response (IR) process.