Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
DFIR-O365RC — PowerShell module for Office 365 and Azure log collection | Kitploit
Tools/GitHubGitHub/anssi-fr/dfir-o365rc
ForensicsDigital ForensicsCloud SecurityIncident ResponseLog Analysis
GitHubanssi-fr/dfir-o365rc

DFIR-O365RC

PowerShell module for Office 365 and Azure log collection

View Repository
28234111 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

DFIR-O365RC

Publish Docker image to Dockerhub Publish module to PowerShell Gallery


Table of contents:

  1. Module description

  2. Installation and prerequisites

    1. Using Docker
    2. Manual Installation
  3. Managing the DFIR-O365RC application

    1. Creating the application
    2. Updating the application
    3. Removing the application
  4. Permissions and license requirements

  5. Functions included in the module

  6. Files generated

DFIR-O365RC was presented at SSTIC 2021 (Symposium sur la sécurité des technologies de l'information et des communications). Slides and a recording of the presentation, in French, are available here.

⚠️ On March 31, 2024, Microsoft deprecated the authentication method we used for DFIR-O365RC. This led to the release of the version 2.0.0 in August 2024, with breaking changes regarding authentication and a global refactoring of the code. ⚠️

Module description

The DFIR-O365RC PowerShell module is a set of functions that allow a forensic analyst to collect logs relevant for Microsoft 365 compromises and conduct Entra ID investigations.

The logs are generated in JSON format and retrieved from two main data sources:

  • Microsoft 365 Unified Audit Log ;
  • Microsoft Entra sign-ins logs and audit logs.

Those two data sources can be queried from different endpoints:

Data source / EndpointRetentionPerformanceScope
Unified Audit Log / Exchange Online PowerShell90 daysPoorAll Microsoft 365 logs (Entra included)
Unified Audit Log / Purview180 daysGoodAll Microsoft 365 logs (Entra included)
Unified Audit Log / Office 365 Management API *7 daysGoodAll Microsoft 365 logs (Entra included)
Microsoft Entra logs / Microsoft Graph PowerShell30 daysGoodEntra sign-ins and audit logs only
Microsoft Entra logs / Microsoft Graph REST API30 daysGoodEntra sign-ins and audit logs only

* The Office 365 Management API is intended to analyze data in real time with a SIEM. DFIR-O365RC is a forensic tool, its aim is not to monitor a Microsoft 365 environment in real time.

DFIR-O365RC will fetch data from:

  • Microsoft Entra Logs using Microsoft Graph PowerShell because performance is good and it wraps around the Microsoft Graph REST API ;
  • By default, Unified Audit Log using Exchange Online PowerShell: despite poor performance this is the only usable option for now ;
  • Optionally, Unified Audit Log using Purview. The retention is 180 days, it has good performance but it is still in beta and bugs in the back-end make it unusable for now.

If you are investigating Microsoft 365 malicious activity, the Search-O365 (from Exchange Online PowerShell) will also fetch the Mailbox Audit Log, although the Search-MailboxAuditLog cmdlet is being deprecated.

If you are investigating other Azure resources, with DFIR-O365RC:

  • you can get the Azure Monitor Activity log using the Az.Monitor PowerShell module, with a retention of 90 days. This log focuses on activities in Azure Resource Manager (related to an Azure subscription) ;
  • you can get the Azure DevOps audit log using the Azure DevOps Services REST API, with a retention of 90 days. This log focuses on activities in Azure DevOps (related to an Azure DevOps organization).

Installation and prerequisites

Using Docker

This is the recommended way of using DFIR-O365RC

Just type :

sudo docker pull anssi/dfir-o365rc:latest
sudo docker run --rm -v .:/mnt/host -it anssi/dfir-o365rc:latest

DFIR-O365RC is ready to use:

PowerShell 7.4.2
DFIR-O365RC: PowerShell module for Microsoft 365 and Entra ID log collection
https://github.com/ANSSI-FR/DFIR-O365RC
PS /mnt/host/output>

If you would like to build your Docker image manually, clone the repository and use docker compose (or the legacy docker-compose) to build the image, run the container and mount a volume (in the output/ folder):

sudo docker compose build dfir-o365rc
sudo docker compose run dfir-o365rc
# using legacy Compose V1
sudo docker-compose run dfir-o365rc

Using PowerShell

You can install the module on PowerShell Desktop and PowerShell Core.

Please note that the Connect-ExchangeOnline cmdlet requires Microsoft .NET Framework 4.7.2 or later.

To install the module from the PowerShell Gallery :

Install-Module -Name DFIR-O365RC

You can also install the module manually by cloning the DFIR-O365RC repository, install the required dependencies (check DFIR-O365RC.psd1) and add the DFIR-O365RC directory in one of your PowerShell's modules path.

Managing the DFIR-O365RC application

Creating the application

Once the module is imported, you will need to create an Entra application, which will handle the log collection process for you.

To do so:

  1. Create a self-signed certificate and get the base64-encoded public part:

    On Linux, using PowerShell Core or the Docker container:

Download Tool