A threat hunting exercise using anomalous user agents to detect business email compromise (BEC) in Microsoft 365. The hypothesis: adversaries often don't change default user agents in their offensive tools. By filtering Microsoft 365 authentication telemetry for rare user agents, the Huntress SOC identified the 'AZURECLI/2.47.0 azsdk-python-azure-mgmt-resource' user agent as a suspicious indicator. Out of 85 hits, four successful logins were confirmed malicious — all corroborated by geographic anomalies and IP reputation. The post shares the detection query, IoCs, ATT&CK TTP mapping, and recommends MFA and conditional access policies as preventive controls.

8m read timeFrom huntress.com
Post cover image
Table of contents
User agents as detection technology for BECOn the hunt: How to detect BEC in Office 365Digging deeper into BEC threat huntingUser BaseliningReporting Business Email Compromise in Microsoft 365Detection Technology Augmented by HumansBEC prevention in Microsoft 365
1 Impression