Interactive investigation
Investigate a consent-phishing and endpoint compromise
Correlate identity, cloud app, email, and endpoint evidence into one defensible incident response.
Scenario briefing
A finance analyst reports an unexpected consent prompt after opening a supplier invoice email. Microsoft Defender XDR correlates alerts involving the user, an OAuth application, mailbox activity, and suspicious PowerShell execution on the analyst's device.
Mission
Determine the attack scope, contain the affected assets, preserve useful evidence, and close the incident with the correct classification.
Products
Microsoft Defender XDRMicrosoft Entra IDDefender for Cloud AppsDefender for Endpoint
01
Ready to investigate?
Evidence stays closed until you choose to inspect it. Each decision reveals feedback; later stages unlock as you progress.