Clankerusecase
Microsoft 365 detection coverage
← Back to main site
Home/ Targets/ Microsoft 365

📧Microsoft 365 detections

Clankerusecase tracks 43 detection use cases covering the Microsoft 365 attack surface across 41 MITRE ATT&CK techniques.

Detections targeting Microsoft 365 — Exchange / SharePoint / Teams / OfficeActivity.

Open Detection Library → View on the matrix
43Use cases
41Techniques
60Articles
4Kill-chain phases

Top techniques on Microsoft 365 (25)

Delivery (21)

Email attachment opened from external sender Internal delivery · hunting DSP Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP User clicked through a Safe Links warning page Internal delivery · alerting DS Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator Internal delivery · hunting DSP [LLM] Inbound email from F6 fraud clone domain (ruspromexport-group.ru / info@ruspromexport-group.ru) Bespoke delivery · alerting DS [LLM] Compromised M365 mailbox fan-out of QR-code PDF phishing (UAT-11764) Bespoke delivery · alerting DSP [LLM] Inbound phishing from BEC sender domain 9i6pokerdepot.com (Q2 2026 ClickUp/pixeldrain chain) Bespoke delivery · alerting DSP [LLM] Inbound HTML-attachment lure exploiting Zimbra XSS (CVE-2025-66376) Bespoke delivery · hunting DS [LLM] Inbound phishing email or URL referencing npm look-alike domain npmjs.help Bespoke delivery · alerting DSP [LLM] Law-firm / order-confirmation lure delivering device-code phish via cacoo.com and allianceinvestigators.com Bespoke delivery · hunting DS [LLM] EvilTokens device-code lure email (Acrobat/DocuSign decoy, 'Verify to view') Bespoke delivery · alerting DSP [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Bespoke delivery · hunting DSΣPDDCS [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain Bespoke delivery · alerting DSΣPDDCS [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) Bespoke delivery · alerting DSΣPDD [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP Bespoke delivery · alerting DS [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke delivery · hunting DSΣPDD [LLM] Phishing email impersonating npm support from typosquatted npmjs.help domain Bespoke delivery · alerting DSΣP [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea package Bespoke delivery · alerting DSP [LLM] Inbound phishing email from npmjs.help maintainer-takeover domain Bespoke delivery · alerting DSΣPDD [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS

Installation (5)

M365 admin role assigned to user Internal install · alerting DD M365 mailbox delegation granted Internal install · alerting DD M365 MFA disabled for a user Internal install · alerting DD [LLM] OWAReaper server-side persistence: Owner rights granted to 'Default' user on mailbox folders Bespoke install · alerting DSΣP [LLM] Execution / write of ESET APT Q2-Q3 2025 known-bad SHA256 payload Bespoke install · hunting DSΣPDDCS

Command & Control (3)

[WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [LLM] AgentForger rogue-agent C2: inbound TASK-subject email followed by outbound reply to sender domain Bespoke c2 · hunting DSP [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS

Actions on Objectives (14)

M365 mail-forwarding rule created Internal actions · alerting DD [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD O365 Exfiltration via File Access ESCU actions · hunting P O365 SharePoint Allowed Domains Policy Changed ESCU actions · alerting P O365 SharePoint Suspicious Search Behavior ESCU actions · hunting P Windows InstallUtil Uninstall Option ESCU actions · alerting P [LLM] Bulk M365 / SharePoint / OneDrive file download by a single identity (cloud data theft) Bespoke actions · alerting DSP [LLM] Post-compromise malicious inbox rule for defense evasion (UAT-11764 / ARToken BEC) Bespoke actions · hunting DSDD [LLM] Malicious postmark-mcp BCC email exfiltration to phan@giftshop[.]club Bespoke actions · alerting DSP [LLM] Post-device-code token abuse: mailbox / OneDrive / Teams access from a new IP after device-code sign-in Bespoke actions · alerting DS [LLM] ARToken BEC toolkit: inbox forwarding/hiding rule creation on compromised M365 mailbox Bespoke actions · hunting DSΣ [LLM] Post-device-code malicious inbox rule creation (BEC prep) Bespoke actions · alerting DSP [LLM] postmark-mcp BCC exfil to giftshop.club Bespoke actions · alerting DSΣPDDCS [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) Bespoke actions · alerting DSΣPDD

Recent articles citing Microsoft 365-targeted detections