Skip to main content

Command Palette

Search for a command to run...

The O365 Intrusion-TryHackMe Walkthrough

Updated
•3 min read•View as Markdown
The O365 Intrusion-TryHackMe Walkthrough

What is the first timestamp at which a non-macOS device signed into Marcus Webb’s account? (Format: YYYY-MM-DD HH:MM:SS)

Ans: 2026–08–27 12:28:31

Just after logging in, the attacker accessed a large number of emails within the first few minutes of the session. How many emails were accessed during this window?

Ans: 22

What subject line does the attacker’s inbox rule match on?

Ans: invoice

How much time elapsed between the malicious inbox rule being created and a matching reply email arriving in the mailbox? (e.g. 2 minutes 51 seconds)

  • Rule created: 12:30:10

  • Matching email arrived: 12:41:09

Calculate:

12:41:09 − 12:30:10 = 10 minutes 59 seconds

Ans: 10 minutes 59 seconds

Marcus Webb’s account logged a Teams message that had a link attached to it. What file did this link reference?

Ans: Meridian_Invoice_Batch_Aug2026.pdf

What operating system was used in the suspicious sign-in to David Chen’s account?

Ans: invoice

How much time elapsed between the malicious inbox rule being created and a matching reply email arriving in the mailbox? (e.g. 2 minutes 51 seconds)

  • Rule created: 12:30:10

  • Matching email arrived: 12:41:09

Calculate:

12:41:09 − 12:30:10 = 10 minutes 59 seconds

Ans: 10 minutes 59 seconds

Marcus Webb’s account logged a Teams message that had a link attached to it. What file did this link reference?

Ans: Meridian_Invoice_Batch_Aug2026.pdf

What operating system was used in the suspicious sign-in to David Chen’s account?

Ans: linux

What IP address was used in this same sign-in?

Ans: 91.219.237.88

How much time passed between this message being created and the suspicious sign-in to David Chen’s account? (e.g. 2 minutes 51 seconds)

  • Message created: 13:03:38

  • Suspicious sign-in: 13:27:04

Elapsed time: 23 minutes 26 seconds.

Ans: 23 minutes 26 seconds

The file the attacker downloaded from David Chen’s account was legitimately modified earlier that day. At what time? (Format: YYYY-MM-DD HH:MM:SS)

downloaded file is Q4_Board_Financial_Summary.xlsx

next make sure to set the time range to the earlies of the day

Ans: 2026–08–27 08:27:03

What file stored on the Leadership site had a sensitivity label applied to it by the organization’s data governance, prior to the incident?

Ans: Q4_Board_Financial_Summary.xlsx

What file did the attacker create an external sharing link for?

Ans: Vendor_Onboarding_Notes.docx

What external email address was granted access to this file?

Ans: d.reynolds88@protonmail.com

According to the emails, what is the subject line of the notification sent to this external address by the sharing application?

Ans: David Chen shared “Vendor_Onboarding_Notes.docx” with you

THANK YOU FOR READING!!! ❤️💫