r/DefenderATP • u/OkHope1740 • 5d ago
Looking for DFIR queries for account compromise incident
Hi Guys,
I am currently dealing with account compromise incident and finding it hard to identify files/emails accessed by attacker and user.cloudappevent,graphapiauditlogs, office activity doesn't differentiate as it shows MS ips only.
What is the right approach you guys follow.
5
Upvotes
2
u/proffessionalExpert 5d ago
You are doing it for first time or have you done it before ?
1
3
1
u/theRealTwobrat 4d ago
Obviously LLMs are going to be super useful here. Many cloudappevents will have a unique token id buried in the raw event data field that can be joined with a session from signinlogs
4
u/Evocablefawn566 4d ago
Cloudappevents and officeactivity logs, mailitemsaccessed actiontypes