Detections

OAuth consent phishing pack for Microsoft 365

Seven new detections for consent phishing, inbox rules and Graph API reads from new networks.

Consent phishing now accounts for about one in four business email compromise cases we see. The new pack watches the full sequence: a consent to an unverified publisher, new inbox rules, then Graph reads from a network the user has never used.

All seven rules are live for every Microsoft 365 customer and can be tuned from Detections.

Send us one week of logs. We send back what we found.

Connect one source with a read-only key. Within 48 hours you get a written report of what Wardell would have caught. No contract, and you can disconnect at any time.

Use this free template

Create a free website with Framer, the website builder loved by startups, designers and agencies.