Analytics
Informational
✕
Exchange mailbox delegation permissions added
A user added delegation permissions to an Exchange mailbox.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
- Licensed by:
- Identity Threat Detection (ITDR)
- Licensed by:
- Email Security
- Data source:
- Office 365 Audit
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation: Additional Email Delegate Permissions (T1098.002)
Attacker's goals:
Add delegation permissions to a mailbox for persistence reasons.
Investigative actions:
Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Investigate the IP address associated with the activity. Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents).
- Test period:
- 4 Hours
- Deduplication:
- 1 Day
1 variation:
- Addition of Exchange mailbox delegation permissions with suspicious characteristics Low (parent: Informational)