Business Email Compromise (BEC) Readiness
Identify vulnerabilities in financial verification processes and email authentication infrastructure.
BEC Attack-Path Evaluation Framework
1. Identity & Auth
Password spraying, AiTM phishing, token theft, and legacy auth exposure.
2. Mailbox Rules
External forwarding rules, deletion sweeps, and hidden inbox filters.
3. App Abuse
OAuth malicious application registration and API access abuse.
4. Payment Controls
Wire transfer authorization policies and out-of-band verification steps.