Skip to main content
Microsoft 365 BEC: Malicious Inbox Rules operation cover
COMING SOONIntermediatePRO

Microsoft 365 BEC: Malicious Inbox Rules

An adversary-in-the-middle phishing kit steals an AP manager's Microsoft 365 session token, bypassing MFA. The actor creates hidden inbox rules to collect mail and suppress replies, then hijacks a live vendor payment thread to redirect a six-figure wire transfer. Work the Entra sign-in audit, Exchange Online rule events, and email evidence to reconstruct the chain.

55m
7 tasks
50 points
Pro

Launches in 5 days

Oct 6, 2026

Tuesday, October 6, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

CloudEmailSIEMQuery

What you'll investigate

7 objectives unlock when this operation goes live.

1Locate the hijacked identity
2Trace the initial access point
3Find where the mail is going
4Uncover the cover-up rule
5Identify the phishing portal
6Classify the persistence mechanism
7Recover the fraudulent account details

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Oct 6, 2026, you can jump straight in.

Get Started Free