For Incident Response
Insurance-grade BEC forensics in 48 hours.
Petra traces every M365 attack from root cause to resolution and produces a complete forensic report with the full attacker timeline. Get your complete forensic report within 48 hours with just 5 minutes of setup.
“Petra gave us a complete picture of the breach in three hours. It used to take us three days.”
Senior IR Lead, top-10 US IR firm
Why IR firms choose Petra
Increase margins on every BEC engagement.
When forensics deploys in five minutes and delivers automatically, your cost per engagement drops significantly. You get the same insurance-required deliverable with a fraction of the manual effort.
Guarantee delivery in days, not weeks.
BEC forensics is notoriously unpredictable, which is why most firms charge time and materials. Petra makes the timeline consistent and measurable. You can commit to a guaranteed window and offer a flat rate to every insurance partner, on every engagement.
Spend more time on your highest-value work.
Because the forensic work happens automatically, your analysts stay focused on higher-value engagements. You can grow your BEC volume without pulling capacity from ransomware work.
How the forensics work
Full attacker tracking.
We follow attackers as they pivot between apps, IP addresses, and residential proxies. No matter how they try to obscure their trail, Petra reconstructs every action.
Everything in one place.
All forensic data is consolidated in a single view. Your team no longer needs to jump between Purview, the Exchange admin center, and SharePoint logs to piece together what happened.
Complete reporting, ready to deliver.
Every engagement produces a draft forensic report and an Excel export with all IOCs (attacker IPs, sessions, ASNs), as well as every SharePoint and OneDrive file accessed during the compromise.
No more manual work or access limitations.
Petra automates the entire forensic investigation, so you can say goodbye to message traces and e-discovery queries. We also work with all Microsoft licenses and can reconstruct incidents up to six months old.
Run your last six months through Petra.
Get insurance-grade forensics for the last 6 months of your M365 logs, including past and active attacks, in 48 hours.
5-min setup · 48-hour results
See what's in your last six months of logs.
Run six months of M365 logs through Petra and get insurance-grade forensics within 48 hours. Five minutes to set up with no sales call.