← Back to catalog
Cloud & Identity

RAVEN

Exchange Online mailbox security audit.

Looks for the signs and preconditions of business email compromise — external mailbox forwarding, suspicious inbox rules (external redirects, mail hidden in rarely opened folders, payment or security mail deleted, throwaway rule names), outbound spam policies and transport rules that forward outside the org, SMTP AUTH, disabled mailbox auditing, and Full Access / Send As delegation. Checks SPF, DKIM, and DMARC for each domain; -DnsOnly -Domain runs those checks with no sign-in. Verdict: At Risk / Review / Clean. Requires ExchangeOnlineManagement and Global Reader. Read-only.

Quick Launch

Run RAVEN

Run in an elevated PowerShell window. Downloads raven.ps1 from CursedTechnocrat/TechnicianToolkit and executes it.

Set-ExecutionPolicy Bypass -Scope Process -Force; $f="$(Get-Location)\raven.ps1"; irm https://raw.githubusercontent.com/CursedTechnocrat/TechnicianToolkit/main/raven.ps1 -OutFile $f; [IO.File]::WriteAllText($f,[IO.File]::ReadAllText($f,[Text.Encoding]::UTF8),[Text.UTF8Encoding]::new($true)); & $f
Category
Cloud & Identity
Identifier
RAVEN
Tags
exchange, m365, bec, email-security