---
title: "BEC Threat Hunting: How to Detect Microsoft 365 Compromises"
url: https://daily.dev/posts/bec-threat-hunting-how-to-detect-microsoft-365-compromises-yko18nzvf
source_url: https://www.huntress.com/blog/threat-hunting-for-business-email-compromise-through-user-agents
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:40.362Z
updated: 2026-05-31T08:52:42.918Z
tags: ["microsoft", "azure"]
reading_time: 8
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# BEC Threat Hunting: How to Detect Microsoft 365 Compromises

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 8 min read · 0 upvotes · 0 comments

## Summary

A threat hunting exercise using anomalous user agents to detect business email compromise (BEC) in Microsoft 365. The hypothesis: adversaries often don't change default user agents in their offensive tools. By filtering Microsoft 365 authentication telemetry for rare user agents, the Huntress SOC identified the 'AZURECLI/2.47.0 azsdk-python-azure-mgmt-resource' user agent as a suspicious indicator. Out of 85 hits, four successful logins were confirmed malicious — all corroborated by geographic anomalies and IP reputation. The post shares the detection query, IoCs, ATT&CK TTP mapping, and recommends MFA and conditional access policies as preventive controls.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/threat-hunting-for-business-email-compromise-through-user-agents>

---

Tags: [#microsoft](https://daily.dev/tags/microsoft), [#azure](https://daily.dev/tags/azure)

[View this post on daily.dev](https://daily.dev/posts/bec-threat-hunting-how-to-detect-microsoft-365-compromises-yko18nzvf)
