Evidence formats
Microsoft Entra sign-in log analysis
Export sign-in logs from the Entra admin center or Microsoft Graph and drop them into a case. PastePile maps each status error code to its documented meaning, separates failures from successes, and runs its account compromise pack. Each case gets a timeline, findings that cite the exact records behind them, a list of what the evidence cannot establish, and hunts compiled to Defender KQL, Sentinel KQL, Splunk SPL, Elastic ES|QL and Sigma for the tools you already run.
What you can upload
- Entra sign-in logs from the portal as CSV, where nested fields arrive as JSON inside cells
- Entra sign-in logs from Microsoft Graph as JSON
- Microsoft 365 unified audit log records (common schema JSON/JSONL, or CSV with AuditData) as audit context
What PastePile checks
- A burst of failed sign-ins followed by a success
- Several identities attempted from one source
- Security information changed and privileged roles assigned
- Sign-ins from scripted or command-line clients
- Sign-ins at hours unusual for the account and from several sources in a short window, reported as statistical signals
Every finding cites the records behind it and states what it does not establish. Statistical signals are reported as rarity within your upload and never become findings. ATT&CK mappings describe what a behavior resembles, not proof that an adversary was present.
What it does not do
- Impossible travel is deliberately not claimed: a VPN, a corporate egress gateway or carrier NAT looks the same as a real journey. Two sources in a short window are reported as an observation for you to judge
- An audit operation name alone does not prove success or compromise
Try it
Open the synthetic Entra sign-ins case to see the timeline, findings, unknowns and report without an account. When you are ready, create an account and compare plans.