BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//speaker//3MJCUV
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251020T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:MAGIC Tricks for Microsoft 365 Incident Response: Hands-on AiTM Ph
 ishing and Business Email Compromise Investigations - Sven Ulke\, Alexande
 r Gödeke\, Martin Glück
DTSTART;TZID=Europe/Luxembourg:20261020T101500
DTEND;TZID=Europe/Luxembourg:20261020T121500
DTSTAMP:20261009T050417Z
UID:pretalx-hack-lu-2026-M9973K@pretalx.com
DESCRIPTION:Business Email Compromise is rarely just a mailbox problem any
 more. In recent Microsoft 365 incident response cases\, we increasingly se
 e adversary-in-the-middle phishing\, stolen session cookies\, suspicious s
 ign-ins\, inbox rule abuse\, OAuth-related activity\, mailbox access\, and
  follow-on fraud attempts as parts of the same investigation.\n\nSince 202
 4\, our incident response team has handled a growing number of BEC and AiT
 M phishing cases. In many of them\, we ran into the same operational probl
 em: collecting the right Microsoft 365 evidence quickly\, consistently\, a
 nd in a format that allows actual analysis rather than another round of ma
 nual spreadsheet work.\n\nThis experience led us to build and release **MA
 GIC**\, Microsoft Azure Graph Information Crawler\, an open-source Python 
 toolset for collecting incident-response-relevant data from Microsoft 365 
 environments through Microsoft Graph and preparing it for analysis in tool
 s such as Timesketch or OpenSearch.\n\nIn this two-hour hands-on training
 \, participants will investigate a realistic Microsoft 365 BEC scenario. T
 hey will learn which evidence matters\, how to collect it with MAGIC\, how
  to structure an investigation timeline\, and how to reason about AiTM phi
 shing activity using sign-ins\, message traces\, mailbox artefacts\, and e
 nrichment data. The workshop is not meant as a pure tool demo. It is a pra
 ctical investigation workflow shaped by real incident response work.
LOCATION:Hollenfels
URL:https://pretalx.com/hack-lu-2026/talk/M9973K/
END:VEVENT
END:VCALENDAR
