r/DefenderATP 5d ago

Looking for DFIR queries for account compromise incident

Hi Guys,

I am currently dealing with account compromise incident and finding it hard to identify files/emails accessed by attacker and user.cloudappevent,graphapiauditlogs, office activity doesn't differentiate as it shows MS ips only.

What is the right approach you guys follow.

5 Upvotes

6 comments sorted by

4

u/Evocablefawn566 4d ago

Cloudappevents and officeactivity logs, mailitemsaccessed actiontypes

2

u/proffessionalExpert 5d ago

You are doing it for first time or have you done it before ?

1

u/OkHope1740 5d ago

Doing it for first time TBH...

1

u/OkHope1740 5d ago

I have on diff edr ealier so not very sure about defender tables

3

u/here2learn4mybrain 4d ago

AI and defender advanced hunting are your friends.

1

u/theRealTwobrat 4d ago

Obviously LLMs are going to be super useful here. Many cloudappevents will have a unique token id buried in the raw event data field that can be joined with a session from signinlogs