Analytics BIOC Low

Exchange DKIM signing configuration disabled

A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Defense Evasion (TA0005) Initial Access (TA0001)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001) Phishing (T1566)
Attacker's goals:

An attacker is attempting to evade detection.

Investigative actions:

Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • A recently configured Exchange DKIM signing configuration was disabled Informational (parent: Low)