↳ GitHub sourceSolution

Business Email Compromise - Financial Fraud

Description

[Business Email Compromise (BEC)](https://www.microsoft.com/en-in/security/business/security-101/what-is-business-email-compromise-bec?rtc=1) attacks often aim to commit financial fraud by locating sensitive payment or invoice details and using these to hijack legitimate transactions. This solution, in combination with other solutions listed below, provide a range of content to help detect and investigate BEC attacks at different stages of the attack cycle, and across multiple data sources including AWS, SAP, Okta, Dynamics 365, Microsoft Entra ID, Microsoft 365 and network logs. This content covers all stages of the attack chain from an initial phishing attack vector, establishing persistence to an environment, locating and collecting sensitive financial information from data stores, and then perpetrating and hiding their fraud. This range of content complements the coverage [Microsoft Defender XDR provides across Microsoft Defender products](https://learn.microsoft.com/microsoft-365/security/defender/automatic-attack-disruption). In order to gain the most comprehensive coverage possible customers should deploy the content included in this solution as well as content from the following solutions: 1. Microsoft Entra ID solution for Sentinel 2. Microsoft 365 solution for Sentinel 3. Amazon Web Services 4. Microsoft Defender XDR 5. Okta Single Sign On
Version
3.0.10
Declared author / publisher
Microsoft - support@microsoft.com
Support tier
Microsoft

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-bec_financialfraud
Additional source files 2Solutions/Business Email Compromise - Financial Fraud/Data/Solution_Business Email Compromise - Financial Fraud.jsonsolution-manifest ↗Solutions/Business Email Compromise - Financial Fraud/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.