
Understand whether an account was actually compromised
Suspicious email activity can range from a blocked phishing attempt to a full account takeover involving mailbox rules, stolen tokens, data access or fraudulent messages. SteelCortex helps organise the available evidence so the organisation can distinguish what is confirmed from what is merely suspected.
Evidence we may review
- Sign-in history, authentication events and unusual locations.
- MFA prompts, token activity and session information.
- Mailbox forwarding, inbox rules and delegate permissions.
- Sent items, deleted items and suspicious message activity.
- Changes to passwords, recovery details or privileged roles.
- Related endpoint, cloud or identity alerts where available.
Investigation questions
When did suspicious access begin? Which accounts, messages or files may have been affected? Did the attacker establish persistence? Were other identities targeted? Is there evidence of fraudulent payment instructions, data theft or lateral movement?
Containment and recovery
Recommended actions may include credential reset, session revocation, removal of malicious rules, MFA review, privilege changes, endpoint checks and monitoring of related accounts. Actions are prioritised so urgent containment does not destroy evidence unnecessarily.
Reporting
The investigation can produce a timeline, evidence summary, affected-account assessment, containment record and remediation plan. Where facts remain uncertain, the report states the limitation rather than presenting assumptions as confirmed conclusions.