Analytics BIOC
Low
✕
Exchange anti-phish policy disabled or removed
A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
- Licensed by:
- Identity Threat Detection (ITDR)
- Licensed by:
- Email Security
- Data source:
- Office 365 Audit
ATT&CK tactics: Defense Evasion (TA0005) Initial Access (TA0001)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001) Phishing (T1566)
Attacker's goals:
An attacker is attempting to evade detection.
Investigative actions:
Follow further actions done by the account. Verify that the configuration change was expected. Check for a possible phishing campaign on the organization.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Recently configured Exchange anti-phish policy disabled or removed Informational (parent: Low)