Sven Ulke
Sven Ulke is a Senior Manager in the Incident Response team of an owner-managed IT service provider. He has been working in IT since 2009, starting in system and network administration before moving into DFIR and Incident Response in 2015.
He holds a B.Eng. in Information Technology from DHBW and an M.Sc. in Digital Forensics from Albstadt-Sigmaringen University.
Sven has handled and led investigations and remediation efforts for large-scale security incidents, with a focus on APT cases in multinational environments, including DAX-40 companies. His work covers incident handling, forensic analysis, remediation strategy, and coordinating complex response projects.
Since 2023, he has been driving the development of Incident Response services in his current role, focusing on scalable analysis methods for major security incidents and building a DFIR partner network. He also shares practical knowledge through talks and community formats, and regularly contributes to open-source DFIR projects.
Session
Business Email Compromise is rarely just a mailbox problem anymore. In recent Microsoft 365 incident response cases, we increasingly see adversary-in-the-middle phishing, stolen session cookies, suspicious sign-ins, inbox rule abuse, OAuth-related activity, mailbox access, and follow-on fraud attempts as parts of the same investigation.
Since 2024, our incident response team has handled a growing number of BEC and AiTM phishing cases. In many of them, we ran into the same operational problem: collecting the right Microsoft 365 evidence quickly, consistently, and in a format that allows actual analysis rather than another round of manual spreadsheet work.
This experience led us to build and release MAGIC, Microsoft Azure Graph Information Crawler, an open-source Python toolset for collecting incident-response-relevant data from Microsoft 365 environments through Microsoft Graph and preparing it for analysis in tools such as Timesketch or OpenSearch.
In this two-hour hands-on training, participants will investigate a realistic Microsoft 365 BEC scenario. They will learn which evidence matters, how to collect it with MAGIC, how to structure an investigation timeline, and how to reason about AiTM phishing activity using sign-ins, message traces, mailbox artefacts, and enrichment data. The workshop is not meant as a pure tool demo. It is a practical investigation workflow shaped by real incident response work.