Digital forensics Institution-led

DFIR-O365RC

PowerShell forensic collection module that retrieves Microsoft 365 audit events and Entra sign-in logs for post-incident investigations.

By ANSSI · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
ANSSI
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-3.0
Upstream status
Maintenance unconfirmed
Evidence class
Institution-led

What the sources establish

Origin note

Published under ANSSI’s official repository and described as an incident-response forensic tool.

Reported capabilities

  • Collects Microsoft 365 Unified Audit Log and Entra sign-in/audit records as JSON.
  • Offers Docker and PowerShell installation.
  • Can optionally retrieve Azure Monitor and Azure DevOps audit logs.

Scope and limits

Requires appropriate tenant permissions and Microsoft licensing; the upstream warns its optional Purview retrieval path remains beta/unusable and this is not a live SIEM.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    README defines forensic collection functions, JSON output, Docker and PowerShell installation, and optional Azure sources, while explicitly distinguishing collection from real-time monitoring.

    Read source
  2. license

    Repository license text is GPL version 3.

    Read source
  3. origin / country

    ANSSI describes its GitHub repositories as agency-developed open-source projects.

    Read source
  4. maintenance

    The README documents a v2.0.0 authentication update in August 2024, but no recent release or explicit current maintenance policy was verified.

    Read source
  5. deployment

    README lists Microsoft 365/Entra permissions and an Entra ID P1 requirement for Entra log retrieval.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow