1. Prerequisites
- Confirmed or suspected mailbox compromise
- Access to email platform audit logs
- Access to SIEM
- Access to IdP logs
- Access to mailbox administration tools
2. Step-by-Step Instructions
-
Identify Affected Mailbox
- Confirm mailbox ownership and account details.
-
Establish Timeline
- Determine:
- Initial compromise
- First suspicious activity
- Most recent suspicious activity
- Determine:
-
Review Authentication Activity
- Review:
- Login events
- MFA events
- Geographic anomalies
- Device information
- Review:
-
Review Mailbox Access Activity
- Identify:
- Mailbox logins
- Delegate access
- Administrative access
- Identify:
-
Review Email Activity
- Review:
- Sent messages
- Deleted messages
- Drafts
- Message searches
- Review:
-
Review Configuration Changes
- Review:
- Inbox rules
- Mail forwarding
- Delegates
- OAuth grants
- Review:
-
Identify Attacker Objectives
- Determine:
- Fraud attempts
- Data collection
- Lateral movement
- Persistence
- Determine:
-
Assess Scope
- Determine affected:
- Mailboxes
- Users
- Business units
- Determine affected:
-
Document Findings
- Prepare investigation summary.
-
Escalate and Hand Off
- Provide findings to containment teams.
- Update the incident record.
3. Post-Action
- Preserve mailbox artifacts.
- Document timeline and findings.
- Attach evidence to the incident record.
Contributor
Vishal Thakur
GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
