Practical incident response and DFIR guides from the CICADA IR team.
Business Email Compromise has moved past simple password theft. Modern BEC chains pivot through OAuth consent grants, mailbox forwarding rules, and inbox poisoning. A step-by-step IR workflow for tracing a BEC incident end-to-end in a Microsoft 365 tenant.