{"repo":"ANSSI-FR/DFIR-O365RC","free":true,"listed":false,"github":"https://github.com/ANSSI-FR/DFIR-O365RC","clone":"git clone https://github.com/ANSSI-FR/DFIR-O365RC.git","description":"PowerShell module for Office 365 and Azure log collection","language":"PowerShell","stars":282,"topics":["dfir","office365","azure-active-directory","powershell","forensics","exchangeonline","azure","devops"],"license":"GPL-3.0","category":"deployment-docker-iac","readme_excerpt":"--- Table of contents: 1. Module description 2. Installation and prerequisites 1. Using Docker 2. Manual Installation 3. Managing the DFIR-O365RC application 1. Creating the application 2. Updating the application 3. Removing the application 4. Permissions and license requirements 5. Functions included in the module 6. Files generated DFIR-O365RC was presented at SSTIC 2021 (Symposium sur la sécurité des technologies de l'information et des communications). Slides and a recording of the presentation, in French, are available here. ⚠️ On March 31, 2024, Microsoft deprecated the authentication method we used for DFIR-O365RC. This led to the release of the version 2.0.0 in August 2024, with breaking changes regarding authentication and a global refactoring of the code. ⚠️ Module description The DFIR-O365RC PowerShell module is a set of functions that allow a forensic analyst to collect logs relevant for Microsoft 365 compromises and conduct Entra ID investigations. The logs are generated in JSON format and retrieved from two main data sources: - Microsoft 365 Unified Audit Log ; - Microsoft Entra sign-ins logs and audit logs. Those two data sources can be queried from different endpoints: Data source / Endpoint Retention Performance Scope --- --- --- --- Unified Audit Log / Exchange Online PowerShell 90 days Poor All Microsoft 365 logs (Entra included) Unified Audit Log / Purview 180 days Good All Microsoft 365 logs (Entra included) Unified Audit Log / Office 365 Management API ","default_branch":null,"files":null,"tree":[],"storefront":"/r/ANSSI-FR","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ANSSI-FR/DFIR-O365RC/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}