Clankerusecase
Microsoft 365 detection coverage
← Back to main site
Home/ Targets/ Microsoft 365

📧Microsoft 365 detections

Clankerusecase tracks 40 detection use cases covering the Microsoft 365 attack surface across 42 MITRE ATT&CK techniques.

Detections targeting Microsoft 365 — Exchange / SharePoint / Teams / OfficeActivity.

Open Detection Library → View on the matrix
40Use cases
42Techniques
60Articles
5Kill-chain phases

Top techniques on Microsoft 365 (25)

Reconnaissance (1)

[LLM] SharePoint STS certificate/thumbprint disclosure endpoint accessed from external IP (CVE-2026-55040 recon) Bespoke recon · alerting SΣP

Delivery (21)

Email attachment opened from external sender Internal delivery · hunting DSP Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP User clicked through a Safe Links warning page Internal delivery · alerting DS Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator Internal delivery · hunting DSP [LLM] Quishing delivery: inbound email with QR-code image/PDF attachment and no scannable body URL Bespoke delivery · hunting DSP [LLM] SafePal breach phishing wave: impersonation email with firmware-update / seed-phrase lure Bespoke delivery · hunting DSP [LLM] RecruitTrap recruitment lure via abused PeopleForce (reply.peopleforce.io) ATS relay Bespoke delivery · hunting DSP [LLM] QR-code PDF phishing attachment resolving to workers.dev / pamconj M365 harvesting page (UAT-11764) Bespoke delivery · alerting DS [LLM] Inbound HTML-attachment lure exploiting Zimbra XSS (CVE-2025-66376) Bespoke delivery · hunting DS [LLM] Inbound phishing email or URL referencing npm look-alike domain npmjs.help Bespoke delivery · alerting DSP [LLM] EvilTokens device-code lure email (Acrobat/DocuSign decoy, 'Verify to view') Bespoke delivery · alerting DSP [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Bespoke delivery · hunting DSΣPDDCS [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain Bespoke delivery · alerting DSΣPDDCS [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) Bespoke delivery · alerting DSΣPDD [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP Bespoke delivery · alerting DS [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke delivery · hunting DSΣPDD [LLM] Phishing email impersonating npm support from typosquatted npmjs.help domain Bespoke delivery · alerting DSΣP [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea package Bespoke delivery · alerting DSP [LLM] Inbound phishing email from npmjs.help maintainer-takeover domain Bespoke delivery · alerting DSΣPDD [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS

Installation (3)

M365 admin role assigned to user Internal install · alerting DD M365 mailbox delegation granted Internal install · alerting DD M365 MFA disabled for a user Internal install · alerting DD

Command & Control (2)

[WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS

Actions on Objectives (13)

M365 mail-forwarding rule created Internal actions · alerting DD [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD O365 Exfiltration via File Access ESCU actions · hunting P O365 SharePoint Allowed Domains Policy Changed ESCU actions · alerting P O365 SharePoint Suspicious Search Behavior ESCU actions · hunting P Windows InstallUtil Uninstall Option ESCU actions · alerting P [LLM] Post-quishing cloud token replay: MFA-satisfied sign-in shortly after QR-attachment email Bespoke actions · alerting DSPDD [LLM] Email-hiding inbox rules created post-compromise (BEC / mailbox concealment) Bespoke actions · hunting DSΣP [LLM] Post-compromise M365 defense-evasion inbox rule creation (UAT-11764 mailbox takeover) Bespoke actions · hunting DSΣ [LLM] Malicious postmark-mcp BCC email exfiltration to phan@giftshop[.]club Bespoke actions · alerting DSP [LLM] Post-device-code malicious inbox rule creation (BEC prep) Bespoke actions · alerting DSP [LLM] postmark-mcp BCC exfil to giftshop.club Bespoke actions · alerting DSΣPDDCS [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) Bespoke actions · alerting DSΣPDD

Recent articles citing Microsoft 365-targeted detections