Request Demo →

Solution

Email Compromise Investigation

Trace suspicious account activity, understand what was accessed and build a clear containment and recovery plan.

Email compromise investigation

Understand whether an account was actually compromised

Suspicious email activity can range from a blocked phishing attempt to a full account takeover involving mailbox rules, stolen tokens, data access or fraudulent messages. SteelCortex helps organise the available evidence so the organisation can distinguish what is confirmed from what is merely suspected.

Evidence we may review

  • Sign-in history, authentication events and unusual locations.
  • MFA prompts, token activity and session information.
  • Mailbox forwarding, inbox rules and delegate permissions.
  • Sent items, deleted items and suspicious message activity.
  • Changes to passwords, recovery details or privileged roles.
  • Related endpoint, cloud or identity alerts where available.

Investigation questions

When did suspicious access begin? Which accounts, messages or files may have been affected? Did the attacker establish persistence? Were other identities targeted? Is there evidence of fraudulent payment instructions, data theft or lateral movement?

Containment and recovery

Recommended actions may include credential reset, session revocation, removal of malicious rules, MFA review, privilege changes, endpoint checks and monitoring of related accounts. Actions are prioritised so urgent containment does not destroy evidence unnecessarily.

Reporting

The investigation can produce a timeline, evidence summary, affected-account assessment, containment record and remediation plan. Where facts remain uncertain, the report states the limitation rather than presenting assumptions as confirmed conclusions.

SteelCortex — Built to Think. Engineered to Defend.

Ready to Strengthen Your Cyber Defence?

Let’s build a stronger, more resilient security posture—together.