IT security intelligence. Since 2006.Cloudflare services ↗
Investigations & digital forensics

Email, Microsoft 365 & cloud forensics

Investigate compromised mailboxes, payment diversion, suspicious sharing and cloud account abuse. We connect identity, email and collaboration evidence to explain the sequence of events and the information potentially affected.

Discuss your requirements
Investigator comparing email records with cloud sign-in activity

Define the incident across identities and services

Cloud incidents often cross several systems: an identity provider, a mailbox, shared files, a finance workflow and a supplier conversation. We map the relevant accounts, tenants, administrators and third parties, then agree collection permissions and the period under review. The first objective is a reliable source map, including evidence held by providers or outside your direct control.

Preserve available records before the picture changes

We assess sign-in and audit records, message traces, mailbox configuration, forwarding, delegated access, application permissions and collaboration activity available under the engagement. Retention and event detail vary by product, licence and configuration; Microsoft’s audit retention guidance is linked below. The collection records the query, time range, export method and known gaps. We avoid assuming that today’s settings describe the account’s state during the incident.

Investigate business email compromise and payment diversion

A fraudulent payment request can originate from a compromised account, a lookalike domain or an altered conversation. We examine relevant messages and headers, authentication context, mailbox changes and the chronology of instructions. Finance records and verification calls can help distinguish the technical compromise from the payment decision. We provide the evidence needed for the client to coordinate with its bank, advisers or authorities; payment reversal remains their process.

Assess access, sharing and possible exposure

We correlate activity to identify affected accounts, files and relevant sessions, taking account of available log coverage. A successful sign-in, a file download and confirmed disclosure are different findings. The report states which of these is supported and where evidence is insufficient. Shared links, guest accounts, applications and administrative changes are reviewed when they could explain continued access or a wider incident.

Connect the investigation to recovery

Findings inform containment and restoration decisions with the system owner: access revocation, identity review, correction of unsafe sharing and validation of configuration changes. We keep a record of these actions so they can be distinguished from suspicious activity. The final briefing explains the supported timeline, exposure assessment, unresolved questions and monitoring improvements that would make a future investigation more conclusive.

Investigate a changed supplier payment instruction

A typical business email compromise enquiry begins with a payment request that appears to have changed. We can examine the agreed message trail, relevant sign-ins, mailbox configuration and available sharing records to test competing explanations. The question may concern a compromised internal account, an external impersonator or an altered conversation. Financial recall and legal steps remain with the responsible parties while technical evidence is assessed.

Review delegates, forwarding and application access

Access to a mailbox can involve more than an interactive password sign-in. Delegated permissions, forwarding rules and applications may be relevant to the investigation. We identify the available records for the selected services and explain which activity they can support. Changes made during containment are recorded separately from the activity under investigation so the timeline remains understandable.

Establish evidence availability early

Cloud investigation depends on the records the environment retained and the access available to collect them. We review service settings, relevant time periods and provider or administrator dependencies before setting expectations. A missing event may reflect limited coverage rather than an absence of activity. The report should state these gaps where they affect conclusions about access or possible information exposure.

What you receive

  • Account, service and evidence-source map
  • Documented log and message collection
  • Email compromise or cloud activity timeline
  • Evidence-based exposure assessment with stated gaps
  • Recovery validation priorities and logging recommendations
  • Mailbox, identity and application-access investigation scope
  • Event chronology separating suspected activity from response changes

Common questions

Can you investigate when the attacker’s account is outside our organisation?

We can examine your authorised evidence and relevant public information. Access to another organisation’s private account or provider-held records requires the appropriate authority and process.

Do missing logs mean there was no breach?

No. We report the available coverage and explain which conclusions cannot be reached. Other sources may help, but they do not automatically replace missing records.

Do you need all our emails?

Not necessarily. Collection can be targeted by accounts, dates and relevant issues, with expansion only where the investigation justifies it.

Can you investigate a shared mailbox?

Yes, within an authorised scope. We examine the available evidence for the mailbox and the identities, delegates or applications able to access it, noting any limitation on attributing an action to an individual.

Can you prove that a particular attachment was read?

That depends on the specific records available and what they actually record. We distinguish delivery, access, download and inferred use where the evidence supports those distinctions.

Further reading: Microsoft — audit log retention policies

What’s your next
technology challenge?

Talk to our team