+31 88 8040 777
  Most attacked platform among SMEs

Microsoft 365 Security & Forensic Investigation

Almost every SME uses Microsoft 365, and that is precisely why these are the most attacked accounts right now. Sessions are stolen, MFA is bypassed, and attackers read your email unnoticed for months. ZETA hardens your environment and investigates incidents down to the last detail.

Token stolen
BEC attack
Forensics
Hardened

Session token theft: MFA bypassed without you noticing

The most dangerous attack technique of the moment also works when you have MFA enabled

How the attack works

1
Phishing email
An employee receives a fake Microsoft login page. The page looks identical.
2
Employee logs in + approves MFA
The attacker intercepts the traffic in real time and forwards it to the real Microsoft servers.
3
Session token intercepted
The attacker obtains a valid, MFA-verified session token, so the password and MFA are no longer needed.
4
Invisible access for months
Email forwarding rules, data exfiltration, identity fraud, all without you seeing any alert.

How ZETA detects and stops this

Conditional Access Policies
Block access from unknown countries, devices or networks, even with a valid token.
Token binding & FIDO2 keys
Session tokens bound to the specific device, so stolen tokens are useless.
Microsoft Entra ID Protection
AI detects risky sign-ins and automatically blocks suspicious sessions.
24/7 audit log monitoring
ZETA continuously monitors your M365 logs for suspicious activity, forwarding rules and mass mailings.
Anti-phishing & DMARC/DKIM/SPF
Ensures attackers cannot spoof email from your domain and that phishing emails are blocked.

Our Microsoft 365 services

From preventive hardening to forensic investigation after an incident

M365 Hardening & Security Audit

We analyse your entire Microsoft 365 configuration: admin roles, MFA settings, Conditional Access, legacy authentication, app permissions and more. You get a prioritised list with concrete improvement points.

Identity & Access Management

Setting up Microsoft Entra ID (Azure AD) with least privilege, separated admin accounts, Privileged Identity Management (PIM) and Identity Protection. No one has more rights than necessary.

Email security (DMARC/DKIM/SPF)

Attackers can no longer spoof emails from your domain. We configure DMARC, DKIM and SPF correctly and monitor for anomalies. Protects your customers and your reputation.

Forensic Investigation after an Incident

Is your M365 account compromised? ZETA reconstructs the full timeline: when did attackers gain access, what data was viewed or exfiltrated, were any forwarding rules created? Including perpetrator profiling and a legally usable report.

Audit Log Monitoring (24/7)

Continuous monitoring of your Microsoft 365 logs: suspicious sign-ins, mass file downloads, unusual forwarding rules, admin changes. We alert you immediately when anomalies occur.

Awareness Training for M365 Risks

Your employees are the first line of defence. ZETA provides targeted training on phishing via Microsoft look-alikes, suspicious OAuth permissions and the safe use of Teams, SharePoint and OneDrive.

9 in 10
SME businesses use Microsoft 365
#1
Most attacked cloud platform
MFA ≠
Protection against session token theft
€270k
Average damage per SME cyberattack

Your M365 hacked? ZETA carries out forensic investigation

When a Microsoft 365 account is compromised, fast and thorough investigation is crucial, for recovery, but also for possible legal steps and insurance handling.

Reconstruct the full timeline
When did attackers gain access? What did they do in hour 1, day 3, week 2?
Map out the data breach
Which emails, files or personal data were viewed or exfiltrated? Essential for the GDPR notification obligation.
Perpetrator profiling
IP addresses, tools used, countries, attack pattern, for the police report and insurer.
Remediation & recovery advice
Restore the account, remove forwarding rules, revoke tokens, harden the configuration.
Direct contact for an M365 incident

What is in the forensic report?

Exact access moments (date, time, IP, location)
Overview of affected accounts and rights
List of files accessed or downloaded
Rules created and changes to the configuration
Perpetrator profiling (origin, attack technique)
GDPR assessment (notification obligation applicable or not)
Recommendations to prevent recurrence

Legally usable: The report is prepared in a way that is usable for filing a police report and for your cyber insurance.

Ready to secure your Microsoft 365 environment?

Whether you want to harden proactively or have had an incident, ZETA helps you quickly and thoroughly.

Request an M365 Security Audit Report an incident

Urgent? Call directly: 088 804 0777 (available 24/7 for active incidents)

Have your M365 environment checked

Leave your details and we will contact you within 1 business day.