10 Things to Know Before You Work on Your Next M365 BEC

Ida Musheyev-Polishchuk, Natasha Vij

BSides NYC 2024 · Day 1 · Tech - Blue

In an insightful talk at BSides NYC, Ida Musheyev-Polishchuk and Natasha Vij, both from Strauss-Friedberg's Digital Forensics and Incident Response (DFIR) team, shed light on the intricacies of investigating Business Email Compromise (BEC) incidents within Microsoft 365 (M365) environments. Titled "10 Things to Know Before You Work on Your Next M365 BEC," their presentation provided a practical guide for cybersecurity analysts and incident responders, focusing on crucial steps and "low-hanging fruit" that can lead to quick wins in complex investigations. The speakers emphasized that while BECs can sometimes appear less complicated than other cyber incidents like ransomware, they often involve multiple compromised users and sophisticated persistence mechanisms, necessitating a structured and detailed approach.

AI review

Competent, practitioner-level IR guidance on M365 BEC investigations from two consultants who clearly do this work daily. Nothing here will surprise an experienced DFIR analyst, but the structured 10-point framework tied to a concrete simulation makes it useful for responders earlier in their careers or teams standing up M365 IR capability for the first time.

Watch on YouTube