Ethical hacker : Microsoft 365 Email Penetration Test
Budget: ₹12,500 – ₹37,500 INR
I need a seasoned ethical hacker to put our Microsoft 365 email stack through its paces. Your mission is to uncover—then safely prove—any weaknesses that could lead to email spoofing or sensitive-data leakage. We are concentrating exclusively on the cloud tenant; no on-prem Exchange servers are in scope this round.
Here’s what I expect:
• Reconnaissance and exploitation attempts against the Microsoft 365 mail flow, Exchange Online configurations, and related DNS records (SPF, DKIM, DMARC).
• Validation of security controls such as Conditional Access, MFA, and mail-flow rules that guard against spoofing.
• Inspection of data-loss-prevention policies, eDiscovery settings, SharePoint/OneDrive links, and any other vectors where email might leak files or messages.
• Clear evidence of each successful finding: steps, tools (e.g., PowerShell, Burp Suite, Metasploit, Kali, or M365 Security Center utilities), and the business impact.
• Actionable hardening guidance aligned with Microsoft best practices.
Deliverables at the end of the engagement:
1. Technical report detailing vulnerabilities, proof-of-concept screenshots or scripts, and severity ratings.
2. Executive summary that a non-technical stakeholder can digest in five minutes.
3. Debrief call to walk through results and answer questions.
All testing must follow an ethical approach and stay within the agreed scope and time window. If you have recent experience weaponizing misconfigured Exchange Online settings—or shutting those holes fast—let’s talk.
Here’s what I expect:
• Reconnaissance and exploitation attempts against the Microsoft 365 mail flow, Exchange Online configurations, and related DNS records (SPF, DKIM, DMARC).
• Validation of security controls such as Conditional Access, MFA, and mail-flow rules that guard against spoofing.
• Inspection of data-loss-prevention policies, eDiscovery settings, SharePoint/OneDrive links, and any other vectors where email might leak files or messages.
• Clear evidence of each successful finding: steps, tools (e.g., PowerShell, Burp Suite, Metasploit, Kali, or M365 Security Center utilities), and the business impact.
• Actionable hardening guidance aligned with Microsoft best practices.
Deliverables at the end of the engagement:
1. Technical report detailing vulnerabilities, proof-of-concept screenshots or scripts, and severity ratings.
2. Executive summary that a non-technical stakeholder can digest in five minutes.
3. Debrief call to walk through results and answer questions.
All testing must follow an ethical approach and stay within the agreed scope and time window. If you have recent experience weaponizing misconfigured Exchange Online settings—or shutting those holes fast—let’s talk.