Interactive investigation

Investigate a consent-phishing and endpoint compromise

Correlate identity, cloud app, email, and endpoint evidence into one defensible incident response.

DifficultyIntermediateEstimated time30 minPrimary domainRespond to security incidents

Scenario briefing

A finance analyst reports an unexpected consent prompt after opening a supplier invoice email. Microsoft Defender XDR correlates alerts involving the user, an OAuth application, mailbox activity, and suspicious PowerShell execution on the analyst's device.

Mission

Determine the attack scope, contain the affected assets, preserve useful evidence, and close the incident with the correct classification.

Products

Microsoft Defender XDRMicrosoft Entra IDDefender for Cloud AppsDefender for Endpoint
01

Ready to investigate?

Evidence stays closed until you choose to inspect it. Each decision reveals feedback; later stages unlock as you progress.