Analytics BIOC Low

Exchange malware filter policy removed

A user removed an Exchange malware filter policy, which may prevent the detection of malware.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses (T1562) Impair Defenses: Disable or Modify Tools (T1562.001)
Attacker's goals:

An attacker is attempting to evade detection.

Investigative actions:

Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other security policies have been changed or removed. Monitor for signs of malware in future messages.

Test period:
N/A (single event)
Deduplication:
1 Day