BEC Example: A Fictional Microsoft 365 Incident Walkthrough
A fictional AiTM business email compromise rebuilt from its Microsoft 365 logs: spray, token replay, inbox rules, forwarding, OAuth consent, fake invoice.
This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.
A fictional AiTM business email compromise rebuilt from its Microsoft 365 logs: spray, token replay, inbox rules, forwarding, OAuth consent, fake invoice.
The first hour after a Microsoft 365 business email compromise: stop the money, keep the logs, revoke sessions and remove persistence, in the right order.
Reading MailItemsAccessed records in a BEC case: Sync vs Bind, InternetMessageId, throttling, licensing, and telling the attacker's reads from the user's.
How to spot an illicit OAuth consent grant in the Unified Audit Log and Entra audit logs, which scopes matter, and how to remove the app's access.
How to analyze Entra ID sign-in logs in a BEC case: key fields, error codes, impossible travel and its false positives, spray, MFA fatigue, legacy auth.
How AiTM phishing steals Microsoft 365 sessions despite MFA, and how to detect the token replay in Entra ID sign-in logs and the Unified Audit Log.
How attackers use inbox rules and forwarding in a BEC, how to find them in the Unified Audit Log and with Get-InboxRule, and how to tell them from real ones.
Reading the Unified Audit Log in a BEC case: the AuditData JSON, the operations to filter on, and how SessionId and UniqueTokenId link actions to sign-ins.
Walkthrough: load a Purview audit export and Entra sign-in logs into M365 Forensics, then read the verdict, findings, timeline and remediation list.
How to investigate business email compromise in Microsoft 365: which logs to pull, what to look for in each, how to tie actions to the attacker's session.