1. Prerequisites
- Confirmed mailbox compromise
- Completion of BEC investigation activities
- Access to email administration platform
- Access to Identity Provider
- Access to affected mailbox
2. Step-by-Step Instructions
-
Confirm Affected Mailbox
- Verify affected account details.
-
Disable Attacker Access
- Revoke:
- Sessions
- Tokens
- Active authentication
- Revoke:
-
Reset Credentials
- Force password reset.
- Require MFA re-registration where appropriate.
-
Remove Malicious Inbox Rules
- Remove:
- Forwarding rules
- Auto-delete rules
- Hidden rules
- Remove:
-
Remove Mail Forwarding
- Disable:
- External forwarding
- Suspicious forwarding destinations
- Disable:
-
Remove Unauthorised Access
- Remove:
- Delegates
- Shared access
- OAuth grants
- Remove:
-
Review Mailbox Configuration
- Validate:
- Security settings
- Mail flow settings
- Access controls
- Validate:
-
Monitor for Continued Activity
- Review:
- Authentication attempts
- Mailbox changes
- New rules
- Review:
-
Validate Containment
- Confirm:
- Attacker access removed
- Mailbox secured
- No malicious configuration remains
- Confirm:
-
Escalate and Hand Off
- Coordinate with recovery activities.
- Update the incident record.
3. Post-Action
- Document all containment actions.
- Preserve evidence of malicious configuration.
- Record validation results.
- Participate in recovery activities.
Contributor
Vishal Thakur
GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
