Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0373 — Detection Strategy for Addition of Email Delegate Permissions
DET0373

Detection Strategy for Addition of Email Delegate Permissions

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN1051 Analytic 1051
Office Suite

Detection of anomalous or unauthorized mailbox delegation activity (e.g., Add-MailboxPermission, Default/Anonymous mailbox permissions, Gmail delegation setup).

m365:unified Add-MailboxPermission, UpdateFolderPermissions
[DelegatePermissionLevel] Threshold for unexpected delegate roles such as FullAccess or SendAs.
[FolderTargetScope] Mailbox folder targeted by delegation (Inbox, Root, Calendar, etc.).
[DelegatorToDelegatePairing] Pairings of delegate and delegator users that are expected.
[MailflowAnomalyThreshold] Spike in outbound mail after delegate addition, used to catch phishing or mass exfil.
AN1052 Analytic 1052
Windows

Execution of PowerShell commands that modify mailbox permissions using Exchange cmdlets (e.g., Add-MailboxPermission), often tied to BEC or post-compromise persistence.

WinEventLog:Security EventCode=4688 m365:unified PowerShell: Add-MailboxPermission
[PowerShellCmdletFilter] Exchange cmdlets to include or exclude based on scope (e.g., Add-MailboxPermission, Set-MailboxFolderPermission).
[ExecutionParent] Flag suspicious script or interactive shell launch by non-admins.
[TimeWindow] Window in which Add-MailboxPermission is followed by anomalous usage (e.g., SendAs events).

Detected Techniques

1

Details

MITRE ID
DET0373
STIX ID
x-mitre-detection-strategy--679edb0f-4fa0-4929-9ffd-881d9f82263d
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.