Hack.lu 2026

MAGIC Tricks for Microsoft 365 Incident Response: Hands-on AiTM Phishing and Business Email Compromise Investigations

Business Email Compromise is rarely just a mailbox problem anymore. In recent Microsoft 365 incident response cases, we increasingly see adversary-in-the-middle phishing, stolen session cookies, suspicious sign-ins, inbox rule abuse, OAuth-related activity, mailbox access, and follow-on fraud attempts as parts of the same investigation.

Since 2024, our incident response team has handled a growing number of BEC and AiTM phishing cases. In many of them, we ran into the same operational problem: collecting the right Microsoft 365 evidence quickly, consistently, and in a format that allows actual analysis rather than another round of manual spreadsheet work.

This experience led us to build and release MAGIC, Microsoft Azure Graph Information Crawler, an open-source Python toolset for collecting incident-response-relevant data from Microsoft 365 environments through Microsoft Graph and preparing it for analysis in tools such as Timesketch or OpenSearch.

In this two-hour hands-on training, participants will investigate a realistic Microsoft 365 BEC scenario. They will learn which evidence matters, how to collect it with MAGIC, how to structure an investigation timeline, and how to reason about AiTM phishing activity using sign-ins, message traces, mailbox artefacts, and enrichment data. The workshop is not meant as a pure tool demo. It is a practical investigation workflow shaped by real incident response work.


Business Email Compromise and AiTM phishing investigations in Microsoft 365 environments often become messy quickly. Relevant evidence may be spread across Microsoft Graph API endpoints, audit logs, sign-in data, message traces, mailbox artefacts, conditional access events, and external enrichment sources. In real incidents, responders frequently work under time pressure, with partial access, unclear tenant configuration, and stakeholders asking difficult questions early:

  • Was the account actually compromised?
  • How did the attacker get in?
  • Is there evidence of AiTM phishing or session theft?
  • Which mailbox artefacts were accessed or modified?
  • Were inbox rules, forwarding settings, OAuth grants, or other persistence mechanisms abused?
  • Which users, IP addresses, sessions, and messages belong to the same incident?
  • What evidence should be preserved for legal, insurance, or post-incident reporting?

Since 2024, our incident response team has seen a noticeable increase in BEC cases involving Microsoft 365 and AiTM phishing. The tooling gap became hard to ignore. Some workflows relied on ad-hoc Graph API calls. Others depended on manually exported CSV files, inconsistent naming, or large spreadsheets that were difficult to review and even harder to reproduce later.

We built MAGIC to make this part of the response process more repeatable. MAGIC is an open-source Python-based toolset that uses Microsoft Graph to collect Microsoft 365 incident response data, structure the output, and prepare it for analysis in common DFIR workflows.

This workshop is intended for incident responders, SOC analysts, CSIRT members, threat hunters, DFIR consultants, and blue teamers who investigate Microsoft 365 compromises or want to improve their BEC response process.

Participants will work through a realistic BEC investigation scenario based on lessons learned from real-world cases. The training covers both methodology and tooling: what to collect, why it matters, how to collect it safely, what can go wrong, and how to turn raw Microsoft 365 telemetry into a useful investigation timeline.

Sven Ulke

Sven Ulke is a Senior Manager in the Incident Response team of an owner-managed IT service provider. He has been working in IT since 2009, starting in system and network administration before moving into DFIR and Incident Response in 2015.

He holds a B.Eng. in Information Technology from DHBW and an M.Sc. in Digital Forensics from Albstadt-Sigmaringen University.

Sven has handled and led investigations and remediation efforts for large-scale security incidents, with a focus on APT cases in multinational environments, including DAX-40 companies. His work covers incident handling, forensic analysis, remediation strategy, and coordinating complex response projects.

Since 2023, he has been driving the development of Incident Response services in his current role, focusing on scalable analysis methods for major security incidents and building a DFIR partner network. He also shares practical knowledge through talks and community formats, and regularly contributes to open-source DFIR projects.

Alexander Gödeke

.

Martin Glück