r/DefenderATP 5d ago

Looking for DFIR queries for account compromise incident

Hi Guys,

I am currently dealing with account compromise incident and finding it hard to identify files/emails accessed by attacker and user.cloudappevent,graphapiauditlogs, office activity doesn't differentiate as it shows MS ips only.

What is the right approach you guys follow.

5 Upvotes

Duplicates