
COMING SOONIntermediatePRO
Microsoft 365 BEC: Malicious Inbox Rules
An adversary-in-the-middle phishing kit steals an AP manager's Microsoft 365 session token, bypassing MFA. The actor creates hidden inbox rules to collect mail and suppress replies, then hijacks a live vendor payment thread to redirect a six-figure wire transfer. Work the Entra sign-in audit, Exchange Online rule events, and email evidence to reconstruct the chain.
55m
7 tasks
50 points
ProLaunches in 5 days
Oct 6, 2026
View Pro plansTuesday, October 6, 2026 at 9:00 AM
Pro unlocks this operation at launch.
Training Tools
CloudEmailSIEMQuery
What you'll investigate
7 objectives unlock when this operation goes live.
1Locate the hijacked identity
2Trace the initial access point
3Find where the mail is going
4Uncover the cover-up rule
5Identify the phishing portal
6Classify the persistence mechanism
7Recover the fraudulent account details
Be first when it launches
Create your account and grab Pro before launch. The moment this operation goes live on Oct 6, 2026, you can jump straight in.
Get Started Free