thecomputerguy
Well-Known Member
- Reaction score
- 1,407
Client called with the usual account compromised. Rules were setup today and I know it was today because we had been in contact prior to this. Funny thing about this one is that they actually made a rule for MY EMAIL so that anything I sent her also got moved to the RSS feeds folder so they must have seen some correspondence indicating I was IT.
The malicious actors were trying to get a few grand from someone in her contacts through a Venmo transaction. Typical stuff...
Revoked MFA Sessions
Reset MFA
Reset Password
I asked her if she clicked on something bad today and of course she said no. I looked through her search history and nothing popped out at me.
Upon further investigation it looks like she originally had her token stolen some time ago 10-20 days ago ... it's hard to tell exactly because she was travelling internationally over the holidays and I had to open up her Conditional Access Policy to allow for international logins.
Any easy options I can employ either by CA or something?
Lastly ... Does anyone know is there is a powershell command or some easy way to see when a rule was created exactly? I know it doesn't really matter but I was trying to identify an exact time. MS says to audit the account in Security but by golly ... that place is messy. I tried this command but it wouldn't give me a timestamp
The malicious actors were trying to get a few grand from someone in her contacts through a Venmo transaction. Typical stuff...
Revoked MFA Sessions
Reset MFA
Reset Password
I asked her if she clicked on something bad today and of course she said no. I looked through her search history and nothing popped out at me.
Upon further investigation it looks like she originally had her token stolen some time ago 10-20 days ago ... it's hard to tell exactly because she was travelling internationally over the holidays and I had to open up her Conditional Access Policy to allow for international logins.
Any easy options I can employ either by CA or something?
Lastly ... Does anyone know is there is a powershell command or some easy way to see when a rule was created exactly? I know it doesn't really matter but I was trying to identify an exact time. MS says to audit the account in Security but by golly ... that place is messy. I tried this command but it wouldn't give me a timestamp
Get-InboxRule -Mailbox john@doe.com | fl