Latest News

Blog

M365 Forensic Analysis: Find Account Compromises and Lurking Attackers Before They Cost You

Account compromises are one of the most common, and most expensive ways businesses lose money to cybercrime today. Once an attacker gains access to a single employee account, they can quietly create rules, access files, impersonate staff, and set up persistence that remains long after the initial entry.

The challenge is that many compromises don’t look like “a breach” in the moment. They look like normal business activity until it’s too late.

That’s why we offer an M365 Forensic Analysis: a retrospective 6‑month analysis of your Microsoft 365 environment designed to uncover evidence of past compromises, identify attackers who may still be present, and highlight who is actively targeting your users right now.

What is an M365 Forensic Analysis?

Our M365 Forensic Analysis is a 6‑month lookback across your Microsoft 365 tenant. It is built to surface:

  • Forensic details of past account compromises (what happened and how)
  • Currently lurking attackers (activity that suggests someone is still inside)
  • Leftover persistence from previous intrusions (mechanisms that allow re-entry)
  • Attackers actively targeting your employees, even if they haven’t successfully gained access yet

This isn’t a quick “score” or a surface-level scan. It’s designed to help you answer the questions that matter:

  • Did an attacker access our environment in the last 6 months?
  • If so, which account(s) were involved?
  • What did they do, email, files, sharing, apps, forwarding rules?
  • Is anyone still inside?
  • Are we currently being targeted, and who is being targeted?

Why account compromises matter (in plain terms)

When an attacker compromises an employee account, the impact can be immediate and real-world:

  • Fraud and financial loss: attackers impersonate staff to redirect payments or request gift cards/wires.
  • Operational disruption: access issues, lost data, or locked-down accounts that halt workflows.
  • Reputational harm: customers receive malicious emails “from you,” or sensitive info is exposed.
  • Long tail risk: even if the attacker is removed, persistence and rogue apps can enable them to return.

In many incidents, the largest costs aren’t technical, they’re the business consequences: downtime, confused customers, delayed billing, and leadership time pulled into damage control.

What we review in your M365 environment

To conduct the analysis, we gather 6 months of activity from Microsoft 365 sources including:

  • Entra (identity and sign-in activity)
  • Exchange (mailbox and mail flow activity)
  • OneDrive and SharePoint (file access and sharing activity)
  • Teams (relevant collaboration activity)
  • And other supporting signals, depending on your environment

This breadth matters because modern compromises don’t live in just one place. An attacker may enter through email, then move to file access, then establish persistence via applications or configuration changes.

How we detect both obvious and subtle attacker behavior

Attackers range from low-effort “spray and pray” attempts to sophisticated operators who mimic normal user behavior. Our approach is designed to separate noise from true risk.

1) We analyze classic compromise indicators

We look at well-known signals such as:

  • Impossible travel
  • Use of VPNs
  • Unusual sign-in patterns

Important note: these signals can be malicious, but they can also be benign (for example: legitimate travel, mobile carrier routing, or business VPN use). That’s why we don’t stop there.

2) We use computed behavioral baselines

We build and use behavioral baselines to search for patterns that are harder to detect signals more consistent with sophisticated attacker behavior. This helps identify activity that “looks normal” at a glance, but isn’t normal for your environment or that specific user.

3) We prioritize what deserves your attention

Not every alert deserves the same level of concern. A key outcome of the analysis is clarity: which findings are low-level background threat activity versus the indicators that point to real compromise or persistence.

What you get: your Autopsy Report

When the analysis is complete, you receive an Autopsy Report that covers:

1) Past or currently lurking attackers (with forensic details)

  • Which accounts show signs of compromise
  • What the attacker did (and when)
  • The highest-impact actions and risk areas

2) Attackers targeting your environment (low-level and sophisticated)

  • Threat activity aimed at your users
  • Who is being targeted
  • Which activity is likely noise vs. likely serious

3) Rogue applications and persistence mechanisms

  • Suspicious or unauthorized applications
  • Hidden persistence that may remain from past attacks
  • Items that may allow re-entry or ongoing access

The goal is to turn uncertainty into a clear set of next steps: what happened, what’s still risky, and what should be remediated first.

Who should consider an M365 Forensic Analysis?

This is especially valuable if:

  • You’ve seen suspicious email behavior (unexpected sends, weird rules, unexplained deletions)
  • Employees report unusual prompts or access issues
  • Your industry is frequently targeted (finance, healthcare, legal, construction, professional services, nonprofits)
  • You want to validate your security posture with evidence, not assumptions
  • You’ve never performed a lookback after a suspected incident (or you’re not sure)

Even if you don’t think you’ve been breached, this type of lookback can reveal targeting and early indicators before they become a full incident.

Ready to confirm what’s happening in your M365 tenant?

CSI secures, monitors, and supports your IT so you can focus on growth. Serving Central & Southwest Florida. Call +1‑844‑340‑5060 or email [email protected]

Nick

CSInvestigator Admin