Hack.lu 2026

Martin Glück


Session

10-20
10:15
120min
MAGIC Tricks for Microsoft 365 Incident Response: Hands-on AiTM Phishing and Business Email Compromise Investigations
Sven Ulke, Alexander Gödeke, Martin Glück

Business Email Compromise is rarely just a mailbox problem anymore. In recent Microsoft 365 incident response cases, we increasingly see adversary-in-the-middle phishing, stolen session cookies, suspicious sign-ins, inbox rule abuse, OAuth-related activity, mailbox access, and follow-on fraud attempts as parts of the same investigation.

Since 2024, our incident response team has handled a growing number of BEC and AiTM phishing cases. In many of them, we ran into the same operational problem: collecting the right Microsoft 365 evidence quickly, consistently, and in a format that allows actual analysis rather than another round of manual spreadsheet work.

This experience led us to build and release MAGIC, Microsoft Azure Graph Information Crawler, an open-source Python toolset for collecting incident-response-relevant data from Microsoft 365 environments through Microsoft Graph and preparing it for analysis in tools such as Timesketch or OpenSearch.

In this two-hour hands-on training, participants will investigate a realistic Microsoft 365 BEC scenario. They will learn which evidence matters, how to collect it with MAGIC, how to structure an investigation timeline, and how to reason about AiTM phishing activity using sign-ins, message traces, mailbox artefacts, and enrichment data. The workshop is not meant as a pure tool demo. It is a practical investigation workflow shaped by real incident response work.

topic: hack.lu
Hollenfels