Best Detection of 2026 Series: Deepfake Executive BEC Payment Fraud
This rule detects a multi-stage Business Email Compromise (BEC) attack involving executive impersonation via look-alike domains, followed by the creation of suspicious inbox rules (forwarding/deletion) by the victim, and concurrent external communication (Teams/Zoom meeting invites) from a newly created account. It correlates these activities to identify sophisticated payment fraud campaigns.
Microsoft Sentinel (KQL)

