
PowerShell module for Office 365 and Azure log collection

DFIR-O365RC was presented at SSTIC 2021 (Symposium sur la sécurité des technologies de l'information et des communications). Slides and a recording of the presentation, in French, are available here.
⚠️ On March 31, 2024, Microsoft deprecated the authentication method we used for DFIR-O365RC. This led to the release of the version 2.0.0 in August 2024, with breaking changes regarding authentication and a global refactoring of the code. ⚠️
The DFIR-O365RC PowerShell module is a set of functions that allow a forensic analyst to collect logs relevant for Microsoft 365 compromises and conduct Entra ID investigations.
The logs are generated in JSON format and retrieved from two main data sources:
Those two data sources can be queried from different endpoints:
| Data source / Endpoint | Retention | Performance | Scope |
|---|---|---|---|
| Unified Audit Log / Exchange Online PowerShell | 90 days | Poor | All Microsoft 365 logs (Entra included) |
| Unified Audit Log / Purview | 180 days | Good | All Microsoft 365 logs (Entra included) |
| Unified Audit Log / Office 365 Management API * | 7 days | Good | All Microsoft 365 logs (Entra included) |
| Microsoft Entra logs / Microsoft Graph PowerShell | 30 days | Good | Entra sign-ins and audit logs only |
| Microsoft Entra logs / Microsoft Graph REST API | 30 days | Good | Entra sign-ins and audit logs only |
* The Office 365 Management API is intended to analyze data in real time with a SIEM. DFIR-O365RC is a forensic tool, its aim is not to monitor a Microsoft 365 environment in real time.
DFIR-O365RC will fetch data from:
If you are investigating Microsoft 365 malicious activity, the Search-O365 (from Exchange Online PowerShell) will also fetch the Mailbox Audit Log, although the Search-MailboxAuditLog cmdlet is being deprecated.
If you are investigating other Azure resources, with DFIR-O365RC:
This is the recommended way of using DFIR-O365RC
Just type :
sudo docker pull anssi/dfir-o365rc:latest
sudo docker run --rm -v .:/mnt/host -it anssi/dfir-o365rc:latest
DFIR-O365RC is ready to use:
PowerShell 7.4.2
DFIR-O365RC: PowerShell module for Microsoft 365 and Entra ID log collection
https://github.com/ANSSI-FR/DFIR-O365RC
PS /mnt/host/output>
If you would like to build your Docker image manually, clone the repository and use docker compose (or the legacy docker-compose) to build the image, run the container and mount a volume (in the output/ folder):
sudo docker compose build dfir-o365rc
sudo docker compose run dfir-o365rc
# using legacy Compose V1
sudo docker-compose run dfir-o365rc
You can install the module on PowerShell Desktop and PowerShell Core.
Please note that the Connect-ExchangeOnline cmdlet requires Microsoft .NET Framework 4.7.2 or later.
To install the module from the PowerShell Gallery :
Install-Module -Name DFIR-O365RC
You can also install the module manually by cloning the DFIR-O365RC repository, install the required dependencies (check DFIR-O365RC.psd1) and add the DFIR-O365RC directory in one of your PowerShell's modules path.
Once the module is imported, you will need to create an Entra application, which will handle the log collection process for you.
To do so:
Create a self-signed certificate and get the base64-encoded public part:
On Linux, using PowerShell Core or the Docker container: