Response & reporting

Incident response

Contain a compromised mailbox: inbox-rule sweeps, evidence capture, and case tracking through to closure.

7 min read
Incident checklist and response report

Opening a case

An incident case groups everything about one event: the triggering threat or alert, the affected mailboxes, the actions taken and the timeline. Cases drive your mean time to respond, which is reported in the SOC report.

  1. 1Open Incident response and click New incident, or escalate directly from an alert.
  2. 2Set the tenant, affected mailbox and severity.
  3. 3Write the initial summary — what was observed and when.

Inbox rule sweep

Attackers who take over a mailbox almost always create a hidden forwarding or delete rule. The inbox rule sweep enumerates rules across the tenant's mailboxes and flags the classic signs: forwarding to external addresses, rules that move mail straight to RSS Feeds or Deleted Items, and single-character rule names.

  1. 1In the incident, run Inbox rule sweep against the tenant.
  2. 2Review flagged rules and remove them in the client's admin portal.
  3. 3Record the removal as an action on the case.

Containment checklist

Work the standard playbook and log each step on the case.

  1. 1Reset the user's password and revoke all active sessions and refresh tokens.
  2. 2Re-register MFA if the attacker may have enrolled a device.
  3. 3Remove malicious inbox rules and mailbox delegations.
  4. 4Search for and purge the offending messages across the tenant.
  5. 5Check for outbound spam sent from the mailbox and for any payment or banking-detail changes.
  6. 6Close the case with a root-cause note once containment and recovery are verified.