Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

BECIn-browser BEC triage · Microsoft 365 & Entra ID

Was my Microsoft 365 hacked?

Drop your Purview audit log and Entra ID sign-in / audit exports. Get a business e-mail compromise verdict, the attacker's timeline and what to do next — analysed in your browser with WebAssembly, nothing is uploaded.

  • Nothing uploaded
  • Unified Audit Log + Entra sign-ins
  • Verdict · timeline · remediation

Drop your Microsoft 365 / Entra ID log exports here

Purview audit log CSV, Entra ID sign-in logs (CSV or JSON, interactive and non-interactive) and Entra audit logs. Several files, folders, ZIP and .gz archives are fine.

The sample is a fictional business e-mail compromise (AiTM phishing, inbox rules, forwarding, OAuth consent) in the real export formats.

No export yet? How to get the logs

Your logs never leave this device: they are analysed locally by WebAssembly.

How to get your logs

Three exports from your tenant: the Unified Audit Log (what was done in mailboxes and files), the Entra ID sign-in logs, interactive and non-interactive (who signed in from where), and the Entra ID audit logs (changes to accounts, MFA methods and apps). Take at least 30 days before the first suspicious e-mail.

  1. Export the three logs
  2. Drop the files, the folder or a ZIP here
  3. Analysed in your browser — nothing is uploaded

Needs: the Audit Logs or View-Only Audit Logs role in Microsoft Purview (the Audit Reader and Audit Manager role groups have it) and Reports Reader in Entra ID. Audit (Standard) comes with most Microsoft 365 business and enterprise plans: no extra licence.

  1. Unified Audit Log — start it first (opens in a new tab)

    1. Microsoft Purview portal → Audit.
    2. Set the date range (UTC): at least 30 days before the first suspicious e-mail, 180 days at most per search. Leave Activities and Users empty.
    3. Search, wait for Completed (minutes to hours on a large tenant), open the search → Export → download the CSV.
  2. Entra ID sign-in logs — both tabs (opens in a new tab)

    1. Microsoft Entra admin center → Entra ID → Monitoring & health → Sign-in logs.
    2. Set Date to the longest range offered (30 days with Entra ID P1/P2, 7 days on Free).
    3. On User sign-ins (interactive): Download → JSON (or CSV). Then the same on User sign-ins (non-interactive). Keep the file names.
  3. Entra ID audit logs (opens in a new tab)

    1. Same admin center → Monitoring & health → Audit logs.
    2. Same date range → Download → JSON (the CSV drops modified properties).

Menu names are those of the English portals.

What to drop

  • UAL.csv · Purview export CSV — Unified Audit Log (has an AuditData column)
  • InteractiveSignIns_*.json|csv — Interactive sign-ins
  • NonInteractiveSignIns_*.json|csv — Non-interactive sign-ins — token replay only shows here
  • AuditLogs_*.json · EntraAuditLogs_*.json — Entra ID audit logs

Drop them together — loose files, the whole C:\triage folder or a ZIP; .gz files are fine and overlapping exports are deduplicated. Not needed: the "authentication details" downloads (skipped). Keep the originals untouched as evidence and hash them (SHA-256) before analysis.

Gotchas

  • Retention runs out first in Entra ID: sign-in and audit logs are kept 7 days on Entra ID Free, 30 days with P1/P2. The Unified Audit Log keeps 180 days on Audit (Standard); Audit (Premium) (E5-level licences) keeps licensed users' Exchange, SharePoint, OneDrive and Entra ID records for one year. A licence bought now does not bring back expired logs — export today.
  • Truncated exports look complete: exactly 50,000 rows (Purview export on Audit Standard, or one PowerShell session; Audit Premium exports go up to 1,000,000), 100,000 sign-ins or 250,000 audit records per Entra download means the cap was hit — split by date or by user.
  • Do not open and re-save the CSV in Excel (it damages the AuditData JSON and the dates), and read times as UTC: every export here is in UTC.

What this tool checks

Business e-mail compromise (BEC) almost always leaves traces in Microsoft 365 logs: a sign-in from an unusual network, a stolen session reused elsewhere, an inbox rule that hides replies, forwarding to an outside address, a consented app with mailbox access, a new MFA method for the attacker.

The tool reads the Purview Unified Audit Log (including the AuditData JSON of every record), Entra ID sign-in logs and Entra audit logs, normalises them, and runs detection rules written as data. It then links mailbox and file actions to the sign-in session that performed them — "this rule was created by that attacker session" — and gives a verdict with its reasons.

Detections

  • Inbox rules: forwarding outside, deleting, marking as read or moving mail to RSS Feeds / Archive, filtering on invoice / payment / bank keywords, meaningless rule names.
  • Mailbox forwarding via Set-Mailbox, mail flow rules, delegated mailbox permissions, audit logging turned off.
  • Sign-ins from hosting / VPN networks, impossible travel, one session used from several countries or networks (AiTM token replay), device code phishing, legacy authentication, MFA fatigue, password spraying, Conditional Access blocks followed by success, Entra ID Protection risk.
  • Illicit OAuth consent grants, credentials added to apps, new MFA methods, privileged role assignments, domain federation changes, Conditional Access changes.
  • MailItemsAccessed spikes, mass SharePoint / OneDrive downloads, mailbox searches for payment keywords, mass deletions.
  • Each finding lists its evidence rows and MITRE ATT&CK techniques; the rules are open (rules.json) and reviewable.

Limitations

  • A clean verdict only covers the period and the sources you provided. Standard audit keeps 180 days, Entra sign-ins 7–30 days in the portal: export early.
  • Heuristics point, they do not prove: a sign-in from a cloud provider may be your own VPN, a forwarding rule may be legitimate. Confirm with the account owners.
  • The Unified Audit Log has no geolocation: countries and networks are borrowed from the Entra sign-ins of the same IP address.
  • Very large exports: up to 400,000 events are kept in memory per analysis; split bigger exports by date range.
  • Message trace, Get-InboxRule output and Defender alerts are not read yet.

FAQ

Are my logs uploaded anywhere?

No. The files are read by your browser and analysed by a WebAssembly module in a Web Worker on your device. Nothing is sent to a server; you can disconnect from the network after the page has loaded.

How do I know if my Microsoft 365 account was hacked?

Look for the attacker's footprints: sign-ins from networks or countries the user never uses, a session reused from another place, inbox rules or forwarding the user did not create, a new MFA method, an app consent. Export the audit and sign-in logs as described above and drop them here: the verdict lists which of these were found.

What is a suspicious inbox rule?

A rule the user did not create that forwards mail outside, deletes it, marks it read or moves it to a folder nobody reads (RSS Feeds, Archive, Conversation History), often filtering on words like invoice, payment or bank, and often with a name like "." or "..". It is the most common sign of business e-mail compromise.

Why does resetting the password not stop the attacker?

Adversary-in-the-middle phishing steals the session cookie after MFA; OAuth consents, app secrets, forwarding rules and extra MFA methods survive a password change. Revoke sessions, remove the rules, forwarding, app consents and unknown MFA methods too — the remediation checklist lists what applies.

Which licence do I need for these logs?

Audit (Standard) is included in most Microsoft 365 and Office 365 business and enterprise plans and keeps the Unified Audit Log for 180 days; on some business plans auditing was not switched on by default, so check it (Get-AdminAuditLogConfig in Exchange Online PowerShell). MailItemsAccessed is part of Audit (Standard) and on by default for E3/E5 users (it used to be Premium-only). Audit (Premium), with E5-level licences, keeps licensed users' Exchange, SharePoint, OneDrive and Entra ID records for one year, up to 10 years with the add-on. Entra ID sign-in and audit logs are kept 7 days on Entra ID Free and 30 days with P1/P2; reading sign-ins through Microsoft Graph also requires P1/P2.

Is this an official Microsoft tool?

No. It is an independent, free and non-commercial tool by a digital forensics practitioner. See the trademark notice on this page.