Microsoft at Your BEC and (API) Call: Auditing Mailbox Item Access for Incident Response

No ratings

Presented at SecTor 2024 by

Concerned about business email compromise (BEC) attacks? Until recently, organizations using Office 365 for email had no way to audit access to individual mailbox items unless they paid for the premium E5-level license. Microsoft has recently enabled all customers to access these logs - but accessing them and getting the data into an actionable format is still a daunting task. In this talk, I'll show how you can leverage readily-available technologies to pull the mailbox audit logs into your SIEM and datalake solution, giving visibility into individual mailbox item access logs, and potentially reducing your PHI/PII exposure risk in the event of a cybersecurity incident.