A threat hunting exercise using anomalous user agents to detect business email compromise (BEC) in Microsoft 365. The hypothesis: adversaries often don't change default user agents in their offensive tools. By filtering Microsoft 365 authentication telemetry for rare user agents, the Huntress SOC identified the 'AZURECLI/2.47.0 azsdk-python-azure-mgmt-resource' user agent as a suspicious indicator. Out of 85 hits, four successful logins were confirmed malicious — all corroborated by geographic anomalies and IP reputation. The post shares the detection query, IoCs, ATT&CK TTP mapping, and recommends MFA and conditional access policies as preventive controls.
Table of contents
User agents as detection technology for BECOn the hunt: How to detect BEC in Office 365Digging deeper into BEC threat huntingUser BaseliningReporting Business Email Compromise in Microsoft 365Detection Technology Augmented by HumansBEC prevention in Microsoft 3651 Impression