What this tool checks
Business e-mail compromise (BEC) almost always leaves traces in Microsoft 365 logs: a sign-in from an unusual network, a stolen session reused elsewhere, an inbox rule that hides replies, forwarding to an outside address, a consented app with mailbox access, a new MFA method for the attacker.
The tool reads the Purview Unified Audit Log (including the AuditData JSON of every record), Entra ID sign-in logs and Entra audit logs, normalises them, and runs detection rules written as data. It then links mailbox and file actions to the sign-in session that performed them — "this rule was created by that attacker session" — and gives a verdict with its reasons.
Detections
- Inbox rules: forwarding outside, deleting, marking as read or moving mail to RSS Feeds / Archive, filtering on invoice / payment / bank keywords, meaningless rule names.
- Mailbox forwarding via Set-Mailbox, mail flow rules, delegated mailbox permissions, audit logging turned off.
- Sign-ins from hosting / VPN networks, impossible travel, one session used from several countries or networks (AiTM token replay), device code phishing, legacy authentication, MFA fatigue, password spraying, Conditional Access blocks followed by success, Entra ID Protection risk.
- Illicit OAuth consent grants, credentials added to apps, new MFA methods, privileged role assignments, domain federation changes, Conditional Access changes.
- MailItemsAccessed spikes, mass SharePoint / OneDrive downloads, mailbox searches for payment keywords, mass deletions.
- Each finding lists its evidence rows and MITRE ATT&CK techniques; the rules are open (rules.json) and reviewable.
Limitations
- A clean verdict only covers the period and the sources you provided. Standard audit keeps 180 days, Entra sign-ins 7–30 days in the portal: export early.
- Heuristics point, they do not prove: a sign-in from a cloud provider may be your own VPN, a forwarding rule may be legitimate. Confirm with the account owners.
- The Unified Audit Log has no geolocation: countries and networks are borrowed from the Entra sign-ins of the same IP address.
- Very large exports: up to 400,000 events are kept in memory per analysis; split bigger exports by date range.
- Message trace, Get-InboxRule output and Defender alerts are not read yet.
FAQ
Are my logs uploaded anywhere?
No. The files are read by your browser and analysed by a WebAssembly module in a Web Worker on your device. Nothing is sent to a server; you can disconnect from the network after the page has loaded.
How do I know if my Microsoft 365 account was hacked?
Look for the attacker's footprints: sign-ins from networks or countries the user never uses, a session reused from another place, inbox rules or forwarding the user did not create, a new MFA method, an app consent. Export the audit and sign-in logs as described above and drop them here: the verdict lists which of these were found.
What is a suspicious inbox rule?
A rule the user did not create that forwards mail outside, deletes it, marks it read or moves it to a folder nobody reads (RSS Feeds, Archive, Conversation History), often filtering on words like invoice, payment or bank, and often with a name like "." or "..". It is the most common sign of business e-mail compromise.
Why does resetting the password not stop the attacker?
Adversary-in-the-middle phishing steals the session cookie after MFA; OAuth consents, app secrets, forwarding rules and extra MFA methods survive a password change. Revoke sessions, remove the rules, forwarding, app consents and unknown MFA methods too — the remediation checklist lists what applies.
Which licence do I need for these logs?
Audit (Standard) is included in most Microsoft 365 and Office 365 business and enterprise plans and keeps the Unified Audit Log for 180 days; on some business plans auditing was not switched on by default, so check it (Get-AdminAuditLogConfig in Exchange Online PowerShell). MailItemsAccessed is part of Audit (Standard) and on by default for E3/E5 users (it used to be Premium-only). Audit (Premium), with E5-level licences, keeps licensed users' Exchange, SharePoint, OneDrive and Entra ID records for one year, up to 10 years with the add-on. Entra ID sign-in and audit logs are kept 7 days on Entra ID Free and 30 days with P1/P2; reading sign-ins through Microsoft Graph also requires P1/P2.
Is this an official Microsoft tool?
No. It is an independent, free and non-commercial tool by a digital forensics practitioner. See the trademark notice on this page.