Malicious Office 365 Email Rule Breach - On Behalf (via office365)

PremiumReviewedSigma · High · v1
Product
azure
Service
office365
Author
HuntRule
Published
2026-08-20
Updated
2026-08-28

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects attempt to hide emails in order to perform phishing attacks by replacing, for example, financial information from the original email with another email containing attacker's financial information. This technique may also be used to avoid specific email notification to be received by end users in case, for example, of an ongoing breach.

Related detections9 linkedT1566 — drag to rearrange
Suspicious AWS Console AiTM Phishing Kit API Endpoints
Suspicious PowerShell Download of updserc Archive to AppData via ClickFix
Suspicious AWS SES Production Access Request via PutAccountDetails (Cloud Email Abuse)
AWS CloudTrail SSM SendCommand Successful Execution for Instance
Proxy WebDAV MiniRedir Drives Execution from External Shares
Windows WebDAV Temporary File Creation with Suspicious Extensions
Okta FastPass blocks phishing authentication attempts via MFA
Microsoft 365 Threat Management: PST Export via New-ComplianceSearchAction -Export
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Pivot detection · T1566 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.