Business Email Compromise Forensics: Evidence Checklist

A structured forensic evidence checklist for investigating business email compromise incidents, detailing message headers, mailbox rules, authentication logs, and payment diversion artifacts.

September 25, 2026

Business email compromise forensics is a specialized digital investigation methodology that uncovers how attackers infiltrate corporate mailboxes, alter communication flows, and divert funds. When an organization suspects unauthorized account access, investigators must systematically collect volatile evidence before system changes or retention limits erase critical traces. Fast identification of compromised sessions, forwarding rules, and modified banking instructions prevents further financial loss while preserving legal admissibility.

Modern email compromise schemes rarely rely on obvious file-based malware. Attackers frequently harvest credentials through social engineering or bypass multi-factor authentication sessions, establishing persistence directly inside enterprise mail environments such as Microsoft 365 or Google Workspace. A thorough investigation demands methodical extraction and correlation of artifacts across email gateways, tenant directories, and endpoint machines.

Organizations facing active incidents can cross-reference their triage procedures with our foundational digital forensics guide for Indian organizations to maintain defensible evidentiary standards throughout the response lifecycle.

Essential Artifacts for Business Email Compromise Forensics

Reconstructing unauthorized mailbox activity requires collecting data from multiple independent logging planes. Relying solely on message bodies leaves blind spots because attackers routinely delete sent items and alter folder structures to mask their operations.

Evidence CategoryPrimary ArtifactsForensic Value
Authentication LogsEntra ID sign-in logs, unified audit logs, OAuth grantsIdentifies attacker IP addresses, user agents, conditional access states, and session hijack timestamps.
Mailbox ConfigurationInbox rules, sweep rules, transport rules, folder permissionsReveals automated forwarding, deletion filters, and persistence mechanisms configured by the intruder.
Message TransportInternet message headers, message trace logs, SMTP delivery receiptsValidates origin IP hops, cryptographic SPF and DKIM signatures, and external recipient lists.
Financial & Document ContextAltered invoice PDFs, banking details, payment instructionsEstablishes fraud scope, victim communication timelines, and specific transaction diversion targets.
A complete email forensic trail requires corroborating tenant audit logs with transport message traces rather than relying on visible mailbox contents alone.

Analyzing Message Headers and Routing Paths

Internet message headers provide an immutable technical breakdown of an email transit history. When examining suspicious messages or spoofed vendor interactions, investigators analyze the sequence of Received headers from bottom to top to identify the true originating server.

Key header fields requiring forensic scrutiny include:

  • Return-Path: The envelope sender address where non-delivery receipts return, often revealing an attacker controlled domain distinct from the display name.
  • Authentication-Results: Details validation results for Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication (DMARC).
  • X-Originating-IP: The client IP address connecting to the sending mail submission server, providing geographic origin data.
  • Message-ID: A unique identifier assigned by the generating mail server that can be matched against mail transfer agent logs.

When threat actors execute multi-stage attacks involving malware delivery or broader network intrusions, teams should coordinate mailbox analysis with critical ransomware response procedures to verify that credential harvesting did not lead to endpoint compromise.

Detecting Hidden Mailbox Rules and Persistence Mechanisms

Once inside a victim mailbox, attackers establish persistence and conceal ongoing communications from the legitimate owner. The most frequent tactic involves creating inbox processing rules that silently divert incoming vendor replies into obscure folders such as RSS Feeds, Archive, or Conversation History.

Investigators must inspect both client-side and server-side rules using PowerShell or tenant management APIs. Search for rules containing keywords like invoice, payment, bank, wire, statement, transfer, or urgent. Malicious actors frequently configure actions such as MarkAsRead, MoveToFolder, or ForwardTo external email accounts.

Beyond mailbox rules, verify tenant level delegate permissions and application registrations. Rogue OAuth applications granted Mail.ReadWrite or Mail.Send permissions allow persistent mailbox access without needing password re-entry or interactive multi-factor authentication prompts.

Reconstructing Timelines from Sign-in Logs and Message Traces

Building an accurate incident chronology connects unauthorized access points to specific fraudulent communications. Analysts extract sign-in logs spanning at least thirty days prior to the suspected diversion date to detect baseline anomalies.

Review the unified audit log for high risk operations including:

  • UserLoggedIn events originating from unusual geographic locations, VPN exit nodes, or anomalous ASN networks.
  • New-InboxRule and Set-InboxRule operations executed shortly after non-standard sign-ins.
  • MailItemsAccessed actions indicating which specific emails and attachments were viewed or synchronized by third-party sessions.
  • SendAs or SendOnBehalf operations performed by unauthorized delegates or administrative accounts.

If suspicious logins indicate potential mobile device synchronizations or rogue ActiveSync profiles, forensic specialists employ mobile device forensics investigation methods to extract local token caches and messaging artifacts from suspect handheld hardware.

Correlating Payment Requests and Financial Diversion Context

The ultimate objective of business email compromise is illicit fund diversion. Forensic teams must compare the timing of forged invoice transmissions with internal accounting workflows and banking confirmations.

Examine modified PDF attachments for metadata discrepancies, including altered creation timestamps, mismatched author strings, or inconsistent PDF producer software versions. Document all beneficiary bank details, intermediate routing codes, and communication threads used to convince financial staff to execute changes.

Victims of international financial fraud should immediately file incident records with official clearing agencies and the FBI Internet Crime Complaint Center to initiate emergency financial kill-chain recalls through cooperating banking networks. Additionally, organizations can consult public security advisories published by the Cybersecurity and Infrastructure Security Agency for updated threat actor tactics and mitigation guidelines.

Business Email Compromise Investigation Evidence Checklist

Follow this step-by-step checklist during the active phase of an investigation to ensure complete artifact retention:

  1. Preserve Volatile Sessions: Capture active sign-in tokens, terminate all active browser sessions, and reset account credentials across identity providers.
  2. Export Unified Audit Logs: Extract administrative and user action logs covering sixty days, ensuring records include IP addresses, client applications, and mailbox access operations.
  3. Dump Mailbox Rules and Delegates: Run PowerShell scripts across all suspect mailboxes to catalog active forwarding, filtering, and delegation permissions.
  4. Extract Complete Message Headers: Save raw RFC 822 formatted message headers for all fraudulent emails, suspicious vendor notices, and related thread responses.
  5. Conduct Message Trace Queries: Query mail gateway records for delivery status, external recipients, and transport rule matches associated with the compromise timeframe.
  6. Analyze Endpoint and Network Artifacts: Inspect client browser histories, cookie storage, and DNS queries on endpoints used by targeted personnel.
  7. Document Chain of Custody: Calculate cryptographic SHA-256 hashes for all exported log archives, email files, and PDF exhibits before analysis.

Frequently Asked Questions About Business Email Compromise Forensics

What evidence is needed for a business email compromise investigation?

A business email compromise investigation requires raw internet message headers, tenant sign-in logs, unified audit logs, mailbox inbox rules, and message trace records. Investigators also need original financial documents, payment instructions, and communication timelines to establish how the diversion occurred.

How do attackers hide emails in a business email compromise attack?

Attackers hide emails by creating automated mailbox rules that move vendor responses directly to deleted folders, RSS subscriptions, or archive subdirectories. They also mark messages as read instantly, preventing the legitimate account owner from noticing incoming questions or security alerts.

How do forensic investigators trace business email compromise?

Forensic investigators trace business email compromise by mapping authentication IP addresses, analyzing message header routing hops, and auditing tenant event logs. They correlate sign-in timestamps with mailbox modifications to identify the entry point, persistence methods, and data exfiltrated during the intrusion.

Found this helpful?

Share this page with others