<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>M365 Forensics — Blog</title>
    <link>https://www.m365forensics.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Mon, 28 Sep 2026 22:07:45 GMT</lastBuildDate>
    <atom:link href="https://www.m365forensics.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Unified Audit Log Retention, Licensing and Missing Logs</title>
      <link>https://www.m365forensics.com/en/blog/microsoft-365-audit-log-retention-and-gaps</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/microsoft-365-audit-log-retention-and-gaps</guid>
      <description>What Microsoft 365 and Entra ID logs keep, for how long, on which licence, and what a BEC investigation cannot see when a source is missing or disabled.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>BEC Example: A Fictional Microsoft 365 Incident Walkthrough</title>
      <link>https://www.m365forensics.com/en/blog/fictional-bec-incident-walkthrough</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/fictional-bec-incident-walkthrough</guid>
      <description>A fictional AiTM business email compromise rebuilt from its Microsoft 365 logs: spray, token replay, inbox rules, forwarding, OAuth consent, fake invoice.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>BEC Response: What to Do in the First Hour (Microsoft 365)</title>
      <link>https://www.m365forensics.com/en/blog/bec-first-hour-response-microsoft-365</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/bec-first-hour-response-microsoft-365</guid>
      <description>The first hour after a Microsoft 365 business email compromise: stop the money, keep the logs, revoke sessions and remove persistence, in the right order.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>MailItemsAccessed: What It Proves (and What It Doesn&apos;t)</title>
      <link>https://www.m365forensics.com/en/blog/mailitemsaccessed-what-it-proves</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/mailitemsaccessed-what-it-proves</guid>
      <description>Reading MailItemsAccessed records in a BEC case: Sync vs Bind, InternetMessageId, throttling, licensing, and telling the attacker&apos;s reads from the user&apos;s.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Illicit Consent Grant: Investigating Rogue OAuth Apps</title>
      <link>https://www.m365forensics.com/en/blog/illicit-consent-grant-investigation</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/illicit-consent-grant-investigation</guid>
      <description>How to spot an illicit OAuth consent grant in the Unified Audit Log and Entra audit logs, which scopes matter, and how to remove the app&apos;s access.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Entra ID Sign-in Logs Analysis: Risky Sign-ins and Travel</title>
      <link>https://www.m365forensics.com/en/blog/entra-id-sign-in-logs-analysis</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/entra-id-sign-in-logs-analysis</guid>
      <description>How to analyze Entra ID sign-in logs in a BEC case: key fields, error codes, impossible travel and its false positives, spray, MFA fatigue, legacy auth.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>AiTM Phishing Detection: Finding Token Replay in Entra ID</title>
      <link>https://www.m365forensics.com/en/blog/aitm-phishing-token-replay-detection</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/aitm-phishing-token-replay-detection</guid>
      <description>How AiTM phishing steals Microsoft 365 sessions despite MFA, and how to detect the token replay in Entra ID sign-in logs and the Unified Audit Log.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Check Inbox Rules for a Hacker in Microsoft 365</title>
      <link>https://www.m365forensics.com/en/blog/malicious-inbox-rules-and-forwarding</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/malicious-inbox-rules-and-forwarding</guid>
      <description>How attackers use inbox rules and forwarding in a BEC, how to find them in the Unified Audit Log and with Get-InboxRule, and how to tell them from real ones.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Unified Audit Log Investigation: Fields That Matter for BEC</title>
      <link>https://www.m365forensics.com/en/blog/unified-audit-log-investigation</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/unified-audit-log-investigation</guid>
      <description>Reading the Unified Audit Log in a BEC case: the AuditData JSON, the operations to filter on, and how SessionId and UniqueTokenId link actions to sign-ins.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Analyze the Unified Audit Log in Your Browser</title>
      <link>https://www.m365forensics.com/en/blog/analyze-microsoft-365-audit-logs-in-your-browser</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/analyze-microsoft-365-audit-logs-in-your-browser</guid>
      <description>Walkthrough: load a Purview audit export and Entra sign-in logs into M365 Forensics, then read the verdict, findings, timeline and remediation list.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Export the Unified Audit Log and Entra Sign-in Logs</title>
      <link>https://www.m365forensics.com/en/blog/export-unified-audit-log-and-entra-sign-in-logs</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/export-unified-audit-log-and-entra-sign-in-logs</guid>
      <description>Step-by-step export of the Purview Unified Audit Log and Entra ID sign-in and audit logs for a BEC case: roles, row limits, PowerShell paging, pitfalls.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Microsoft 365 BEC Investigation: A Practitioner&apos;s Guide</title>
      <link>https://www.m365forensics.com/en/blog/microsoft-365-bec-investigation-guide</link>
      <guid isPermaLink="true">https://www.m365forensics.com/en/blog/microsoft-365-bec-investigation-guide</guid>
      <description>How to investigate business email compromise in Microsoft 365: which logs to pull, what to look for in each, how to tie actions to the attacker&apos;s session.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>