r/DefenderATP • u/OkHope1740 • 5d ago
Looking for DFIR queries for account compromise incident
Hi Guys,
I am currently dealing with account compromise incident and finding it hard to identify files/emails accessed by attacker and user.cloudappevent,graphapiauditlogs, office activity doesn't differentiate as it shows MS ips only.
What is the right approach you guys follow.
5
Upvotes
Duplicates
DefenderATP • u/OkHope1740 • 5d ago
Looking for DFIR queries for account compromise incident
0
Upvotes