What problem does it solve?
Business Email Compromise (BEC) attacks bypass traditional email security because they contain no malicious links or attachments, relying purely on social engineering to trick employees into transferring funds or sharing sensitive data. This Skill provides structured detection procedures to identify these fraud attempts before financial damage occurs.
Core Features & Use Cases
- BEC-Specific Email Rules: Configure detection for VIP display name spoofing, Reply-To mismatches, financial keywords with urgency language, and first-time senders to finance staff.
- Behavioral Analytics & Account Compromise Detection: Baseline communication patterns, detect impossible travel, and alert on inbox forwarding rule creation (T1114.003).
- Financial Process Controls: Implement dual-authorization for wire transfers and out-of-band verification for payment detail changes.
- Use Case: A SOC analyst investigating a suspicious vendor bank-change request uses this Skill to check Reply-To mismatches, verify sender authentication gaps, and enforce callback verification before payment processing.
Quick Start
Use this skill to build detection rules and investigation procedures for business email compromise attempts targeting our finance team.