Office 365 Security, Forensics and Incident Response

Digital forensic experts investigate hundreds of Office 365 incidents per year and help strengthen your security.

Diverse O365 Investigations Inform Proven Forensics Methodology

Kroll’s forensic specialists have spent years investigating O365 security incidents of all sizes, types and complexity. These include business phishing attacks, email compromises, insider threats, compromise of privileged accounts, SMTP relay attacks, etc.

Our experts’ unique experience not only informs Kroll’s robust forensic methodology, but also primes our approach with the agility to recognize and respond to new forms of cyberattacks.

Our investigations deliver actionable information by reconstructing a detailed timeline of a bad actor’s activity in your environment:

  • Identifying search terms the actor ran and the messages that may have been viewed as a result of those search terms
  • Isolating mail client vs. web browser–based access
  • Identifying and compiling emails auto–forwarded by unauthorized mail rules
  • Looking across an entire O365 tenant to identify other suspicious/unauthorized access, including OneDrive and SharePoint file access
  • If available, we will also run original phishing campaign discovery and analysis

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...