Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Series

Investigating a Microsoft 365 BEC

6 posts in this series. Read them in order or jump to any one.

  1. Microsoft 365 BEC Investigation: A Practitioner's Guide

    How to investigate business email compromise in Microsoft 365: which logs to pull, what to look for in each, how to tie actions to the attacker's session.

  2. How to Export the Unified Audit Log and Entra Sign-in Logs

    Step-by-step export of the Purview Unified Audit Log and Entra ID sign-in and audit logs for a BEC case: roles, row limits, PowerShell paging, pitfalls.

  3. How to Analyze the Unified Audit Log in Your Browser

    Walkthrough: load a Purview audit export and Entra sign-in logs into M365 Forensics, then read the verdict, findings, timeline and remediation list.

  4. Unified Audit Log Investigation: Fields That Matter for BEC

    Reading the Unified Audit Log in a BEC case: the AuditData JSON, the operations to filter on, and how SessionId and UniqueTokenId link actions to sign-ins.

  5. Entra ID Sign-in Logs Analysis: Risky Sign-ins and Travel

    How to analyze Entra ID sign-in logs in a BEC case: key fields, error codes, impossible travel and its false positives, spray, MFA fatigue, legacy auth.

  6. Unified Audit Log Retention, Licensing and Missing Logs

    What Microsoft 365 and Entra ID logs keep, for how long, on which licence, and what a BEC investigation cannot see when a source is missing or disabled.

All posts in this series