Digital forensics Institution-led
DFIR-O365RC
PowerShell forensic collection module that retrieves Microsoft 365 audit events and Entra sign-in logs for post-incident investigations.
By ANSSI · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Digital forensics
- Developer or maintainer
- ANSSI
- Recorded country
- France
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- GPL-3.0
- Upstream status
- Maintenance unconfirmed
- Evidence class
- Institution-led
What the sources establish
Origin notePublished under ANSSI’s official repository and described as an incident-response forensic tool.
Reported capabilities
- Collects Microsoft 365 Unified Audit Log and Entra sign-in/audit records as JSON.
- Offers Docker and PowerShell installation.
- Can optionally retrieve Azure Monitor and Azure DevOps audit logs.
Scope and limits
Requires appropriate tenant permissions and Microsoft licensing; the upstream warns its optional Purview retrieval path remains beta/unusable and this is not a live SIEM.
Inspect the research evidence 5 source observations
identity / capabilities / deployment
README defines forensic collection functions, JSON output, Docker and PowerShell installation, and optional Azure sources, while explicitly distinguishing collection from real-time monitoring.
Read sourcelicense
Repository license text is GPL version 3.
Read sourceorigin / country
ANSSI describes its GitHub repositories as agency-developed open-source projects.
Read sourcemaintenance
The README documents a v2.0.0 authentication update in August 2024, but no recent release or explicit current maintenance policy was verified.
Read sourcedeployment
README lists Microsoft 365/Entra permissions and an Entra ID P1 requirement for Entra log retrieval.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow