home.social

#ediscovery — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ediscovery, aggregated by home.social.

  1. Revisiting M365 eDiscovery Without Premium Features

    I was curious about what that old e3 licensing experience was like in 2026, so I took a look.

    #eDiscovery #M365 #MicrosoftPurview
    newsletter.mikemcbride365.com/

  2. What is the Future of eDiscovery in M365?

    No testing this week, just my personal thoughts on the future, and maybe some discussion

    #M365 #eDiscovery #Purview

    newsletter.mikemcbride365.com/

  3. 🚨 Incident Response
    ===================

    Executive summary: This guide provides a 10-step investigation workflow for Business Email Compromise (BEC) incidents within Office 365 environments. It is designed to help incident response teams identify, collect and analyse mailbox- and tenant-level artifacts relevant to impersonation, forwarding abuse and account takeover.

    Technical details:
    • The guide emphasises review of mailbox audit logs, message trace, mail-flow rules (transport rules) and eDiscovery exports as primary evidence sources.
    • Key artefacts highlighted include unusual SendAs/SendOnBehalf events, newly created inbox rules that forward or delete messages, anomalous OAuth app consent events, and unexpected mailbox folder movements.
    • Tenant-level indicators include changes to mail-flow configuration, additions to send connectors, and modifications to conditional access or MFA settings.

    Analysis and detection guidance:
    • The workflow recommends correlating mailbox audit events with message trace entries and Azure AD sign-in logs to link message delivery anomalies to authentication or session anomalies.
    • Detection focus areas are: new inbox rules that create forwarding to external addresses, SendAs spikes originating from unusual IPs, and simultaneous role/permission changes across accounts.

    Conceptual implementation (no commands):
    • Collect mailbox and tenant audit data for the suspected timeframe, prioritise mailboxes involved in financial workflows, and preserve eDiscovery exports for chain-of-custody.
    • Use correlation across Exchange Online, Azure AD sign-ins and conditional access changes to establish timeline and scope.

    Best practices and limitations:
    • Best practices include capturing comprehensive audit logs early, documenting access and evidence handling, and validating mail-flow rule histories.
    • Limitations include possible log retention gaps depending on tenant configuration and the need for eDiscovery access to export mailbox content.

    Practical use cases:
    • The guide supports investigations of CFO impersonation scams, vendor invoice fraud, and mass forwarding events used to exfiltrate emails.

    References:
    • Contact for incident support: [email protected]

    🔹 BEC #incident_response #office365 #exchange_online #eDiscovery

    🔗 Source: github.com/PwC-IR/Business-Ema

  4. Taking a Look at Holds in the New Purview eDiscovery

    Not much has changed, but there are some hints at more that may be coming.

    #M365 #Purview #eDiscovery

    newsletter.mikemcbride365.com/

  5. Upcoming retirement of the Purview Premium eDiscovery tool

    Don't let the lost features catch you by surprise. Plus, a little search bug in that new interface.

    #M365 #eDiscovery #Purview

    mcbridem365.substack.com/p/upc

  6. @olivvybee

    Well at least the admin doesn't stand in front of a slide on stage that has 'Privacy' in the background for ironic purposes in the age of #ediscovery of #FreeWebHostingCulture to continue the gaslighting that #FreeWebHosting has brought over the past 20+yrs.

    Progress? ¯\_ಠ_ಠ_/¯

  7. Here is a weird post about #FreeWebHosting #culture that bridges 20+years.

    iF I told you 'Hey, you should really look out for those #Tripod & #AngelFire web hosting users due to their #GangStalking #IDS, /s' from 20+yrs ago but just replaced the web hosting providers with #Instagram & #Facebook, what would you of thought about those #FreeWebHosting users today who are complacent with their #FreeWebHosting #culture of #GangStalking being #investigated
    🤔

    🔮 : 🔎 Certain #ClosedWeb vs. #OpenWeb things would stand out due to Public Scrutiny. Why, aren't you using the #PeriodTrackingApp called #FacebookMessenger currently being used for tracking #Abortion related #crimes? Amazing things started to happen when the #ClosedWeb #SocialMedia place got #OpenWeb'D. Init? 👀👀 🔍

    #PrivateFacebookForums made #Public and the list of names involved in #GangStalking is quite effective and prosecutors love using 18 U.S.C. Sec 241 to hand out 5, 10, 15 to Life Sentences for this #GangStalking behavior btw.

    For one example of this #GangStalking behavior coupled with illegal #Surveillence by the #Landlord found by the residents of a whole neighborhood, btw:

    .... What iF your #Landlord was disclosing when their #Tenants were leaving _their_ residence for coordination of #BreakIns using #SocialMedia to harass the #renter? That would be pretty stupid based on how #ediscovery at #Meta works.

    🔎 WOT iF the #Police just looked the other way because this was under $10k of theft? WOT iF #BodyCam footage was correlated with #PoliceReports to uncover this? 💯🔍

    #FacebookMessenger is not #private

    #FunFact : #MarkZuckerburg lied to you about #privacy

    He told you earlier in his career '#DumbFscks shouldn't trust #Meta.'

    #MARCOM lied to you about #Privacy & #Advertising networks you call #SocialMedia. Duh.

    Not everyone has a #Meta account

    Not everyone has a #Facebook

    Not everyone has an #Instagram

    Not many people even know what a ' #Metaverse ' even IS let alone visit it outside of #Meta per the huge losses at the #VR #AR #MR division of #RealityLabs there in Menlo Park, CA.

    #Prosecutors are already using this #OneWeirdMARCOM trick, 'saying everyone is on something ' when in fact, No, very few people ACTUALLY use this. Did you miss the #RICO documentary about #MarkZuckerburg in 2010 or something? 🤔

    Now they are just weaponizing certain states laws on #abortion to go after your #Mothers and #Daughters for #abortions in #ListOfStates, btw. Read up on which states those #FreeWebHosting companies that are JUST #Advertising companies with #WebHosting btw, 💯, where YOU ARE THE PRODUCT being SOLD, data wise, since you don't pay them, obvs., except now in places in the EU, where they are looking at #OptingOutOfAdvertising & offering a #PaidWebHosting model, duh, due to #Regulations on certain things #ForcedConsent & otherwise, being completely illegal. #GDPR

    📚📰🗞️📡🛰️📺

  8. ⚠️#NUEVO #POSGRADO!!!⚠️ #ProgramadeActualización en “#Algoritmos, #ÉticadelosAlgoritmos, #Perfilamiento, #PruebaDigital e ,#EDiscovery
    🔹️Dir. Dra. PhD Johanna C. Faliero en Facultad de Derecho UBA
    ⛔ÚLTIMOS DÍAS DE INSCRIPCIÓN🔸️CIERRAN EL 22/08⛔
    📌INICIO DE CURSADA: 28/08
    📌Zoom: Lunes 20 a 23 hs
    📧Información: [email protected]
    📧Inscripción:
    [email protected]

  9. Protecting Revenue and Reputation? Reducing Corporate Risk from Departing Employees - Read the complete article at complexd.blog/3W6ePRB. #eDiscovery #Business #CorporateRisk