All playbooks
Incident scenarios · Incident responders and SOC leads
Business email compromise
No malware, no endpoint. A valid login, a mail rule, and an invoice that goes to the wrong account.
Nothing here looks malicious to an endpoint tool, because nothing malicious runs on an endpoint. The evidence is in the mailbox and the sign-in log.
What this does not establish
- Whether money has moved. That is a finance question, and it is urgent.
- Whether the mailbox is still accessible to them. Tokens outlive passwords.
- How many mailboxes. Lateral phishing from an inside address works far better.
0 of 10 ticked
Selected step
DetectStep 1 of 10
Pull the sign-in history for the account
- Impossible travel is weak alone; unusual ASN plus a new device is stronger.
- Legacy auth and app passwords bypass MFA — check whether either was used.
- Start the timeline now: every action, who took it, when.