Skip to main content
Consent Granted: Malicious OAuth App Mailbox BEC operation cover
COMING SOONIntermediatePRO

Consent Granted: Malicious OAuth App Mailbox BEC

A consent-phishing intrusion where an adversary-in-the-middle proxy steals a finance analyst's Microsoft 365 session, then the attacker tricks her into granting a malicious multitenant OAuth application delegated mailbox permissions. The app gets its own client secret for durable access, reads her mailbox over Microsoft Graph, hides vendor replies with an inbox rule, and sends a fraudulent bank-detail-change reply into a live settlement thread. Work the Entra consent and permission-grant audit, the service-principal credential change, the Graph mailbox operations, and the email evidence to reconstruct the chain.

50m
7 tasks
50 points
Pro

Launches in 3 days

Sep 1, 2026

Tuesday, September 1, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

CloudEmailSIEM

What you'll investigate

7 objectives unlock when this operation goes live.

1Incident brief
2Locate the compromised identity
3Identify the application the analyst consented to
4Find the durable-persistence step
5Spot the application driving the mailbox
6Recover the fraudulent account details
7Classify the persistence-credential technique

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Sep 1, 2026, you can jump straight in.

Get Started Free