I correlated Azure sign-in timestamps with Office compliance activity, located the suspected phishing message and used browser history to corroborate interaction with its link. I then reviewed authentication-method changes, mail-filtering rules, sensitive-file activity and outbound messages to test the extent of account abuse.
Viewed
Growing MSSP with Offensive Services
Identity, mailbox and browser correlation
Follow a mailbox compromise through the account
Return to the full story ←