I connected Azure sign-in timestamps with Office compliance activity, located the suspected phishing message and corroborated interaction with its link through browser history. I then reviewed authentication-method changes, inbox rules, file-access activity and sent messages.
Viewed
Growing MSSP with Offensive Services
Correlating identity, email and browser evidence
Tracing invoice fraud through mailbox rules and MFA changes
Return to the full story ←