Identity & Email Incident Response

Follow a mailbox compromise through the account

I reconstructed Microsoft 365 account compromise through Azure sign-in logs, Office compliance records and browser history, then investigated unauthorised MFA registration and inbox rules.

Growing MSSP with Offensive ServicesHands-on identity and email investigation2 min read

I investigated an executive Microsoft 365 mailbox compromise linked to a fraudulent invoice payment. I used Azure sign-in logs and Office compliance records to establish the account timeline, identify repeated failed authentication attempts and locate the first suspicious successful sign-in in the records I reviewed.

I then examined the mailbox for a phishing message around that time. Browser-history analysis corroborated that the user had followed the suspicious link. That connected the email evidence with user activity; the failed sign-ins remained a separate observation rather than proof of the entry method.

I reviewed account changes and found an additional MFA method and mail-filtering rules. I examined Microsoft 365 audit activity for sensitive-file access and messages sent from the account to assess persistence, concealment and the visible scope of the compromise.

The known invoice-fraud conversation was the mailbox abuse identified in that review. I supported reversal of the unauthorised changes and recovery guidance, keeping the conclusion tied to the account activity available in the logs.

Closer to the work

Access and persistence

The account had suspicious successful access alongside repeated failed sign-in attempts. I investigated the access timeline, an added MFA method and mail-filtering rules. The authentication method offered a way to maintain account access; the rules could conceal relevant messages. The record does not establish a particular MFA-bypass technique.

Open this detail ↗
Identity, mailbox and browser correlation

I correlated Azure sign-in timestamps with Office compliance activity, located the suspected phishing message and used browser history to corroborate interaction with its link. I then reviewed authentication-method changes, mail-filtering rules, sensitive-file activity and outbound messages to test the extent of account abuse.

Open this detail ↗
Account recovery and visible scope

The known fraudulent conversation was the mailbox abuse identified in the reviewed evidence. Unauthorised account changes were reversed and the user received recovery and prevention guidance. The investigation scoped the account activity visible in the available identity and audit records.

Open this detail ↗

Skills established through this work

This work connects to

SOC & incident response

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.