Response & reporting
Incident response
Contain a compromised mailbox: inbox-rule sweeps, evidence capture, and case tracking through to closure.
7 min read

Opening a case
An incident case groups everything about one event: the triggering threat or alert, the affected mailboxes, the actions taken and the timeline. Cases drive your mean time to respond, which is reported in the SOC report.
- 1Open Incident response and click New incident, or escalate directly from an alert.
- 2Set the tenant, affected mailbox and severity.
- 3Write the initial summary — what was observed and when.
Inbox rule sweep
Attackers who take over a mailbox almost always create a hidden forwarding or delete rule. The inbox rule sweep enumerates rules across the tenant's mailboxes and flags the classic signs: forwarding to external addresses, rules that move mail straight to RSS Feeds or Deleted Items, and single-character rule names.
- 1In the incident, run Inbox rule sweep against the tenant.
- 2Review flagged rules and remove them in the client's admin portal.
- 3Record the removal as an action on the case.
Containment checklist
Work the standard playbook and log each step on the case.
- 1Reset the user's password and revoke all active sessions and refresh tokens.
- 2Re-register MFA if the attacker may have enrolled a device.
- 3Remove malicious inbox rules and mailbox delegations.
- 4Search for and purge the offending messages across the tenant.
- 5Check for outbound spam sent from the mailbox and for any payment or banking-detail changes.
- 6Close the case with a root-cause note once containment and recovery are verified.