Microsoft 365 Exchange junk email settings modified by a suspicious VPN

이 페이지는 아직 한국어로 제공되지 않으며 번역 작업 중입니다. 번역에 관한 질문이나 의견이 있으시면 언제든지 저희에게 연락해 주십시오.

Goal

Detect when the Exchange junk email settings have been modified by a suspicious VPN.

Strategy

Monitor Microsoft 365 Exchange audit logs to look for the operation Set-MailboxJunkEmailConfiguration. Attackers who have gained unauthorized access to a victim’s account may modify junk email settings to redirect incoming emails. This technique could be used by an attacker to avoid detections focussing on email inbox rules.

Triage and response

  1. Identify any additional unusual behaviors:
    • Previous failed logins.
    • Unexpected VPN usage.
    • Unusual user agent.
  2. Contact the user {{@usr.email}} to determine if they made the change to the junk email configuration.
  3. If {{@usr.email}} is not aware of the activity:
    • Investigate other activities performed by the user {{@usr.email}} using the Cloud SIEM - User Investigation dashboard.
    • Begin your organization’s incident response process and investigate.