DFIR-O365RC
2.0.4
The DFIR-O365RC module will extract logs from the unified audit log (using Exchange Online and Purview), Entra ID Sign In logs, Entra ID Audit Logs, Azure Monitor and Azure DevOps activity logs
Minimum PowerShell version
5.1
Installation Options
Owners
Package Details
Author(s)
- INM-CLOUD@ssi.gouv.fr
Tags
O365 Security Forensics DFIR Exchange Defender AzureAD MSGraph Azure DevOps Purview EntraID Logs
Functions
Connect-AzApplication Connect-AzUser Connect-ExchangeOnlineApplication Connect-ExchangeOnlineUser Connect-MicrosoftGraphApplication Connect-MicrosoftGraphUser Get-AADApps Get-AADDevices Get-AADLogs Get-AzDevOpsActivityLogs Get-AzDevOpsAuditLogs Get-AzDevOpsRestAPIResponseUser Get-AzRMActivityLogs Get-AzureRMActivityLog Get-LargeUnifiedAuditLog Get-MailboxAuditLog Get-MicrosoftGraphLogs Get-O365Defender Get-O365Full Get-O365Light Get-UnifiedAuditLogPurview New-Application Remove-Application Import-Certificate Search-O365 Update-Application Write-Log
PSEditions
Dependencies
-
- Az.Accounts (>= 3.0.2)
- Az.Monitor (>= 5.2.1)
- Az.Resources (>= 7.2.0)
- ExchangeOnlineManagement (>= 3.5.1)
- Microsoft.Graph.Applications (>= 2.20.0)
- Microsoft.Graph.Authentication (>= 2.20.0)
- Microsoft.Graph.Beta.Reports (>= 2.20.0)
- Microsoft.Graph.Beta.Security (>= 2.20.0)
- Microsoft.Graph.Identity.DirectoryManagement (>= 2.20.0)
- PoshRSJob (>= 1.7.4.4)
Release Notes
1.0.0 - Initial release
1.1.0 - Added Get-AADDevices and Get-AzRMActivityLogs functions
1.2.0 - Added Get-AzDevOpsActivityLogs function and added mailobx audit logs retrieval to the Search-O365 function
2.0.0 - Rework of the project: use of an application to do the log collection, instead of an authenticated user. Add Purview
FileList
- DFIR-O365RC.nuspec
- DFIR-O365RC.psm1
- DFIR-O365RC.psd1
- Manage-Applications.ps1
- Get-AADDevices.ps1
- Get-O365.ps1
- Get-AzDevOpsActivityLogs.ps1
- Get-AADLogs.ps1
- Get-AzRMActivityLogs.ps1
- Get-AADApps.ps1
Version History
Version | Downloads | Last updated |
---|---|---|
2.0.4 (current version) | 12 | 11/15/2024 |
2.0.3 | 8 | 10/30/2024 |
2.0.2 | 7 | 10/30/2024 |
2.0.1 | 6 | 10/30/2024 |
2.0.0 | 5 | 10/30/2024 |