This repository contains slides, log scenarios, and additional materials related to the DEF CON 34 workshop "Investigating and Responding to M365 account compromise on a shoestring: Living off the Land Incident Response"
For the scripts used to collect logs like those in these scenarios, as well as BEC investigation playbook, see https://github.com/bitpusher2k/M365IRScripts
For Excel/Calc macros which support rapid manual log analysis, see https://github.com/bitpusher2k/ExcelMacros