PLATFORM/ICES
LIVE — GLOBAL

The costliest attack arrives as an ordinary email.

ICES watches Google Workspace and Microsoft 365 for account takeover and business email compromise — the invoice swap, the 3 a.m. login, the forwarding rule nobody set.

GOOGLE WORKSPACE · M365ATO + BEC · ONE CONSOLE
H00DIES · ICES CONSOLE MONITORING
MAILBOXES
1,847
SIGNALS · 24H
9,312
ACT NOW
3
MEDIAN DETECT
9 min
SECURITY BRIEFING · LOGIN
IMMEDIATE ACTION
0
REVIEW RECOMMENDED
6
LOGIN EVENTS CHECKED 161
ADMIN ACTIVITY · 3
Audit logging disabled · admin@acme-na.com
Admin privilege granted · it-ops@acme-na.com
SECURITY BRIEFING · EMAIL
MALICIOUS CONFIRMED
3
REVIEW LATER
2
"[Urgent] Microsoft 365 password expiry notice" FROM micros0ft-support.example · CONFIRMED THREAT
"Wire account change request (urgent)" FROM examp1e.example · CONFIRMED THREAT
"Invoice.zip payment confirmation" FROM delivery-notice.example · CONFIRMED THREAT
EMAILS CHECKED 9
READ-ONLY APINOTHING INSTALLEDMOCK DATA FOR ILLUSTRATION
Why it exists

BEC is a finance problem before it's an IT problem.

$123K

average loss per BEC incident — paid out through normal finance processes, not a technical exploit.

Hours

is how long you have to recall a fraudulent wire. After that, recovery is the exception, not the rule.

Unread

audit logs record the takeover — login, forwarding rule, OAuth grant — but nobody is reading them at 3 a.m.

SOURCES: FBI IC3 2025 INTERNET CRIME REPORT — FIGURES ARE INDUSTRY AVERAGES; YOUR EXPOSURE MAY DIFFER.
How it plays out

Two attacks. Two timelines.

SCENARIO 01 BEC · INVOICE FRAUD
The vendor's "new bank account"
DAY 1
Email from a lookalike vendor domain enters a real payment thread — registered 6 days earlier.
ICES FLAG · DOMAIN AGE + LOOKALIKE AT FIRST CONTACT
DAY 2
"Updated banking details" arrive with a plausible invoice. Finance queues the change for the next payment run.
DAY 3
Blocked. The flagged thread is escalated, finance confirms with the real vendor by phone, and the transfer never leaves the account.
SCENARIO 02 ATO · 3 A.M. LOGIN
The login nobody was awake for
03:12
Successful login to an executive mailbox from an ASN and device never seen for this account.
03:15
A hidden forwarding rule and a persistent OAuth grant appear — the classic quiet-persistence pair.
03:21
Detected in 9 minutes. Session revoked, rule and grant removed, credentials rotated before a single email was exfiltrated.
ICES FLAG · FWD RULE + OAUTH PERSISTENCE
COMPOSITE SCENARIOS BASED ON FIELD CASES · DETAILS ANONYMIZED
The principle

Rules decide. AI verifies and explains.

40+ SIGNALS · 13 EVIDENCE FAMILIES
Deterministic verdicts

Cross-checked signals drive the rule engine. AI writes the explanation and validates the evidence — a hallucination can't invent a threat, or hide one.

MEASURED BASELINES
Noise stays suppressed

Night-shift logins and GeoIP quirks are learned from your tenant's actual behavior, not a generic exception list — so alerts mean something.

NO SILENT EXCEPTIONS
Whitelists don't override evidence

A trusted sender with decisive compromise evidence still triggers a verdict. Decisive evidence is never whitelisted away.

Evidence

Built to survive a bank's scrutiny.

When money moves, the report has to hold up outside your company — with your bank, your insurer, and law enforcement. ICES collects the evidence itself, first-hand, and keeps it isolated per tenant.

First-hand collection — 19 protocol banners, TLS metadata, and live screenshots captured directly, not quoted from a feed.
30-day tenant-isolated retention — your evidence never commingles with another customer's.
Submission-ready reports — formatted for banks, insurers, and law enforcement, generated from the case record.
Cross-checked, then re-verified — Shodan, Censys, AbuseIPDB, and GreyNoise corroborate; our own collection confirms before anything reaches a verdict.
Operating model

Run it yourself, or let our analysts watch.

Platform Managed
OPERATION Self-operated by your team 24×7 analyst monitoring by h00dies
SUPPORT Business-hours support BEC investigation on every confirmed case
REPORTING Console dashboards and exports Monthly executive report
ADD-ONS Advisory available as an add-on Advisory included
On either model, confirmed breaches hand off losslessly to the h00dies incident response and forensics team — same case record, same evidence, no re-telling the story.
Adoption

About two weeks. Nothing installed.

PRICING · ANNUAL SUBSCRIPTION, BY USER COUNT
STEP 1
Demo & scoping

30-minute walkthrough, tenant scope, and success criteria agreed.

STEP 2 · DAYS
Read-only API connect

Google Workspace or M365 connected read-only — first detections within days.

STEP 3
Onboarding

Alert routing and escalation paths set up — including an SPF, DKIM, and DMARC review.

STEP 4
14-day tuning

Baselines measured on your tenant's real behavior; verdicts reviewed together.

See it work

Scroll — ICES catching a fraud.

SCROLL TO STEP THROUGH A LIVE-STYLE SESSION
STEP 01 · INTEGRATE
Mailboxes plug in, nothing installs.

Google Workspace, Microsoft 365, NAVER WORKS — read-only API connections to the mail platform you already run. No agent, no MX change.

INSIGHT

Deployment is an API consent screen — roughly two weeks to live, matching the ICES rollout stat.

STEP 02 · LOGIN INVESTIGATION
Every login, measured against its owner.

A week of 123 login events collapses into the two that matter — a new country, an impossible hour, an unfamiliar network.

INSIGHT

Baselines are per-account: a night-shift login that is normal for one user stays quiet for that user.

STEP 03 · MAIL ANALYSIS
Nine emails in, three verdicts out.

Received mail is scored and sorted — malicious, suspicious, safe — with the reasoning attached to every verdict.

INSIGHT

Verdicts come from deterministic rules; AI adds the explanation, not the decision.

STEP 04 · LOGIN LOGS AUDIT
The log tells the story in order.

Nine failures from one address, then a success, then audit logging goes dark — the audit view catches the sequence, not just the events.

INSIGHT

Single events look harmless; sequences don't. The audit trail is built to read sequences.

STEP 05 · MALICIOUS EMAIL DETECTION
Caught before finance replies.

SPF, DKIM, DMARC and content scoring converge on each message — the wire-change request scores 82 and is escalated before anyone replies.

INSIGHT

Median detection is measured in minutes — before the reply, not after the loss.

H00DIES · ICES SYNCING
DATA SOURCES · PROVIDER CONNECTIONS
Google Workspace IntegrationCONNECTED
Microsoft 365 IntegrationCONNECTED
NAVER WORKS IntegrationSYNCING
NAVER WORKS EMAIL CSV UPLOAD↑ UPLOAD CSV
READ-ONLY API · NOTHING INSTALLEDMOCK DATA
H00DIES · ICES MONITORING
EVENTS · 7D
123
CRITICAL
2
WARNING
6
NORMAL
115
WARNINGadmin@example.comLOGIN SUCCESS · US
WARNINGfinance@example.comLOGIN SUCCESS · RU
REGION DISTRIBUTION
KR
97
RU
9
US
7
PER-ACCOUNT BASELINES · 7-DAY TRENDMOCK DATA
H00DIES · ICES ANALYZING
RECEIVED
9
MALICIOUS
3
SUSPICIOUS
2
SAFE
3
"[Urgent] Microsoft 365 password expiry notice"security@micros0ft-support.exampleMALICIOUS
"[Notice] Account verification required"no-reply@account-verify.exampleSUSPICIOUS
"Wire account change request (urgent)"ceo@examp1e.exampleMALICIOUS
EVERY VERDICT SHIPS WITH ITS REASONINGMOCK DATA
H00DIES · ICES AUDITING
ALL LOGS · 08/18
FAILEDfinance@example.comLOGIN FAILURE ×9 · 198.51.100.42
WARNINGfinance@example.comLOGIN SUCCESS · 198.51.100.42
CRITICALadmin@example.comAUDIT LOG DISABLED · 203.0.113.156
CRITICALadmin@example.comADMIN PRIVILEGE GRANTED
→ SEQUENCE FLAGGED: brute force → success → audit tampering
SEQUENCES, NOT SINGLE EVENTSMOCK DATA
H00DIES · ICES FLAGGING
EMAIL LIST · AUTH + CONTENT SCORE
"[Urgent] Microsoft 365 password expiry notice"security@micros0ft-support.example✕ SPF✕ DKIM✕ DMARC88
"Wire account change request (urgent)"ceo@examp1e.example✕ SPF✕ DKIM✕ DMARC82
"Security Weekly — this week in security"news@trusted-vendor.example✓ SPF✓ DKIM✓ DMARC0
SPF · DKIM · DMARC · CONTENT SCOREMOCK DATA

30-min demo + 14-day free assessment —
decide on your own data.

READ-ONLY API · NOTHING INSTALLED · YOU OWN THE RESULTS