Exchange anti-phish policy disabled or removed
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection, Email
ATT&CK Tactic
Initial Access (TA0001), Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Phishing (T1566)
Severity
Low
Description
A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign.
Attacker's Goals
An attacker is attempting to evade detection.
Investigative actions
Follow further actions done by the account.
Verify that the configuration change was expected.
Check for a possible phishing campaign on the organization.
Variations
Was this helpful?
