
Part of a 3-lab investigation case on Threat Hunting Labs. This lab is the Threat Hunt angle (1 of 3), scoped to reconstructing valid-account access, Microsoft 365 service fan-out, Graph discovery, mailbox collection and inbox-rule persistence from a BEC alert against a named mailbox.
Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.


Nine branch points across Entra interactive and non-interactive sign-in logs, Microsoft Graph activity, Exchange mailbox audit and Exchange message trace, tying a compromised session to Graph enumeration, OWA mailbox reads and inbox-rule persistence. Cleared every branch with a perfect score and no hints used.

Findings sat at the bottom of the pyramid — IP addresses and a domain, the tier an attacker can swap out in seconds — rather than anything at the TTP or tooling level. That tracks with an intrusion that never touched malware or custom tooling and instead rode legitimate Microsoft 365 session and API activity the entire way through.
Earned the completion certificate for this 3-lab case (Threat Hunt, Incident Response, Detection Engineering).
Verify: https://www.threathuntinglabs.com/certificates/i24dJJsDrmmU