operation: paper-trail · tenant forensics

The Audit That Caught a Ghost

A Microsoft 365 tenant under my administration. A compromised mailbox doesn't crash anything — it just sits there, reading. Nothing looks broken, which is exactly the problem.

[contact]A routine audit pass turned up activity no legitimate user could explain.
[recon]Built forensic tooling on Microsoft Graph with app-only authentication and walked the evidence — sign-in trails, mailbox activity, audit logs — until the picture resolved: compromised credentials.
[assault]Cut the access mid-session — forced password resets with MFA enrollment, revoked every active session and token.
[cleanup]Hardened the tenant so the door wouldn't reopen: tightened authentication and access policies across the board.
[aftermath]Full cleanup, verified through the same audit trail that started it. Quiet tenants get audited anyway — that's the point.
arsenal: microsoft graph (app-only) · sign-in & audit logs · mfastatus: closed