How to Analyze the Unified Audit Log in Your Browser
Walkthrough: load a Purview audit export and Entra sign-in logs into M365 Forensics, then read the verdict, findings, timeline and remediation list.
TL;DR. Open M365 Forensics, drop the Purview audit CSV and the Entra ID sign-in and audit exports (files, a folder or a ZIP), and wait for the progress bar. Check the coverage line first, then read the verdict (Clean / Suspicious / Compromised) and the findings behind it. Every finding has its evidence rows, MITRE ATT&CK techniques and remediation steps. The Incident timeline orders the attacker's actions; Entities lets you pivot on an IP, session or app. Everything runs locally in WebAssembly: the files never leave your machine.
I built the tool for the moment when a small company calls with "the supplier says we sent new bank details, we didn't" and there is no SIEM, only exports. This walkthrough uses the built-in fictional sample so you can follow along without real data.
What you need
- The exports described in how to export the Unified Audit Log and Entra sign-in logs: Purview audit CSV, Entra interactive and non-interactive sign-ins (CSV or JSON), Entra audit logs.
- A recent desktop browser. No install, no account, no upload. After the page has loaded you can disconnect from the network; the analysis still runs.
Accepted inputs, detected from the header or first record rather than the file name:
| Source | Formats read |
|---|---|
| Unified Audit Log | Purview portal CSV; Search-UnifiedAuditLog | Export-Csv output (including the #TYPE line and UTF-16) |
| Entra sign-ins | Portal CSV; portal JSON; Graph signIn JSON; Log Analytics SigninLogs JSON; diagnostic settings {"records": […]} |
| Entra audit | Portal CSV; Graph directoryAudit JSON |
| Containers | JSON arrays, {"value": […]} pages, JSONL, .gz, ZIP, folders |
Step 1: drop everything at once
Use Choose files, Choose a folder or drag the lot onto the drop zone. Don't pre-filter: the tool needs the whole tenant's sign-ins to see a password spray, and the non-interactive file to see token replay. To try it with no data, click Try a sample: it loads a fictional AiTM business email compromise in the four real export formats, clearly labelled as invented.
Files are streamed in 8 MB slices to a Web Worker, so a large UAL does not freeze the page. Up to 400,000 events are kept in memory per analysis; beyond that the tool warns you and you should split the export by date.
Step 2: read the coverage line before the verdict
Under the verdict you get a line such as "366 events from 4 files · 2026-09-14 07:02 → 2026-09-15 16:33 (UTC)" and the count per source (Unified Audit Log, Entra sign-ins, Entra audit). Then warnings for what is missing:
- No Unified Audit Log: inbox rules, forwarding, mailbox and file access cannot be checked.
- No Entra sign-in logs: impossible travel, token replay, MFA fatigue and risky sign-ins cannot be checked.
- No MailItemsAccessed records: which messages were read cannot be established.
A "Clean" verdict with a missing-source warning is not clean. It is "not checked".
Step 3: understand the verdict
The rule is deliberately simple:
| Verdict | Condition |
|---|---|
| Compromised | At least one critical finding, or two different high findings on the same account |
| Suspicious | At least one medium or high finding |
| Clean | No finding of medium or above in the logs provided |
Critical findings include an inbox rule forwarding outside the organisation, mailbox forwarding to an external address, audit logging disabled, federation changes, and the correlation finding "Actions performed from the attacker's session or IP". The Why list under the verdict links to the findings that decided it.
Step 4: review findings and evidence
Each finding card shows its severity, the accounts, the time range, key facts (IP, country, ASN, rule parameters such as ForwardTo or MoveToFolder) and the MITRE ATT&CK techniques. Show the evidence filters the event table to the exact rows behind it, and each row opens a detail sheet with the normalised fields and the original record.
The detections are rules written as data (34 in the current rules.json shipped with the tool, reviewable by anyone), grouped in families:
- Mailbox: inbox rules that forward, delete, hide or filter on payment keywords, odd rule names,
Set-Mailboxforwarding, transport rules, delegation, audit tampering. - Sign-ins: hosting/VPN networks, impossible travel, one session from several places (token replay), device code, legacy authentication, MFA fatigue, password spray, Conditional Access block then success, Entra ID Protection risk.
- Identity and apps: OAuth consent with risky scopes, app credentials, new MFA methods, privileged roles, federation and Conditional Access changes.
- Data: MailItemsAccessed spikes, mass SharePoint/OneDrive downloads, keyword searches, mass deletion.
- Correlation: UAL and audit actions carrying the IP, Session ID or token of a suspicious sign-in.
Read the evidence, not just the title. Threshold findings (for example "300+ mailbox items in an hour") list every event in the window, which can include the user's own activity around the attacker's.
Step 5: walk the incident timeline
The Incident timeline tab lists every event behind a medium, high or critical finding, oldest first, with repeats collapsed ("×23 until 09:02"). It is the draft of your report's chronology: first spray, first attacker sign-in, replay, MFA registration, rules, forwarding, reads, consent, downloads, the fraudulent send. Switch between UTC and local time; keep UTC in the report.
Step 6: pivot on entities
Entities groups accounts, IP addresses, sessions and applications with first/last seen, event counts and countries. Clicking one filters All events to it. Useful pivots:
- The attacker's IP: which other accounts did it touch?
- The replayed Session ID: everything done in that session, across sign-ins and UAL.
- An unknown application: who consented, and what did it access?
All events has free-text search, a source filter and Flagged only. Export the view as CSV (cells that start like a formula are neutralised to prevent spreadsheet formula injection) or the full JSON report.
Step 7: remediation checklist
The Remediation tab turns the findings into ordered steps: revoke sessions, reset credentials and MFA, remove inbox rules and forwarding, remove the consented app, warn contacts, check payments, and so on, each with the reason ("Because of: …"). Ticks stay in that browser tab only. The order and the reasoning are explained in the first hour after a BEC.
Limits you should know
- Heuristics point, they do not prove. A hosting-network sign-in may be your own VPN; the hosting ASN list is hand-maintained.
- The UAL has no geolocation: countries and networks are borrowed from Entra sign-ins of the same IP. With no sign-in file, UAL events have no country.
- Impossible travel uses country centroids when coordinates are missing.
Get-InboxRuleoutput, message trace and Defender alerts are not read yet.
More in retention limits and missing logs. To see a full result explained line by line, read the fictional incident walkthrough.